CVE-2025-39602
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-39602 is a Missing Authorization vulnerability affecting the WooCommerce Product Table Lite plugin, versions n/a through 3.9.5. This issue arises due to incorrectly configured access control security levels, enabling unauthorized users to exploit the vulnerability and gain unintended access to restricted areas of the WordPress site. This could potentially lead to data theft, modification, or unauthorized actions. The vulnerability can be mitigated by implementing proper access control policies and ensuring that the plugin is updated to the latest version, which includes security patches for the identified issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.