CVE-2025-24625
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 24, 2025
CWE ID 862
Summary
CVE-2025-24625 is a Missing Authorization vulnerability affecting the Marco Almeida | Webdados Taxonomy/Term and Role-based Discounts plugin for WooCommerce. This issue arises due to incorrectly configured access control security levels. Exploiters can take advantage of this flaw to gain unauthorized access, posing a significant risk to websites using the affected plugin versions from n/a through 5.1.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.