CVE-2025-31854
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 1, 2025
CWE ID 862
Summary
CVE-2025-31854 is a Missing Authorization vulnerability affecting the Simple Sticky Add To Cart plugin for WooCommerce. The issue arises due to incorrectly configured access control security levels, enabling unauthorized users to exploit the vulnerability. This affects versions of the plugin from n/a through 1.4.5. Successful exploitation could result in unintended actions, such as adding or modifying items in the shopping cart, posing a potential risk to e-commerce sites using the vulnerable plugin.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.