CVE-2025-32593

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 862

Summary

CVE-2025-32593 is a new vulnerability affecting Bytes Technolab's Add Product Frontend for WooCommerce plugin. This missing authorization issue allows unauthorized access to functionalities that should be restricted. The error lies in the plugin's misconfiguration of access control security levels, making it exploitable. Versions of Add Product Frontend for WooCommerce from n/a to 1.0.6 are affected, posing a risk for websites using these versions. Successful exploitation could lead to unintended actions, potentially causing significant damage. It is imperative for users to update their plugins to the latest version or apply appropriate security patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share