CVE-2025-24596

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 24, 2025
Updated: Feb 11, 2025
CWE ID 862

Summary

CVE-2025-24596 is a critical vulnerability affecting WooCommerce Product Table Lite, where access control security levels are not enforced correctly. This issue, identified in versions from n/a through 3.8.7, permits unauthorized users to exploit the missing authorization function and gain unapproved access to the WooCommerce platform. This vulnerability poses a significant risk, as it can lead to unintended modifications, theft of sensitive data, or even system takeover. It is essential for users to update their WooCommerce Product Table Lite plugins as soon as possible to mitigate this exposed risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share