CVE-2025-31580
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-31580 is a vulnerability affecting Anzar Ahmed Ni WooCommerce Product Enquiry. The issue involves missing authorization, allowing unauthorized access to functionality that should be properly constrained by Access Control Lists (ACLs). This flaw affects versions 4.1.8 and below of the plugin, potentially putting WooCommerce websites using these versions at risk. Attackers could exploit this vulnerability to gain unwarranted access to restricted areas, leading to potential data breaches or unintended modifications. It is recommended that WooCommerce site administrators update their product enquiry plugin to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress