CVE-2025-22694
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-22694 is a Missing Authorization vulnerability affecting the Hide Shipping Method For WooCommerce plugin, versions 1.0.0 through 1.5.0. An attacker can exploit this issue to bypass authentication and gain unauthorized access to hidden shipping methods in WooCommerce stores, potentially leading to financial loss or data theft. The vulnerability arises from insufficient access controls, enabling unauthorized users to modify or view sensitive information. It is essential for WooCommerce users to update the plugin to the latest version as soon as possible to mitigate the risk of this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.