CVE-2025-2266

Published Mar 29, 2025

Last updated 2 days ago

CVSS critical 9.8
WordPress
WooCommerce

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2025-2266 affects the Checkout Mestres do WP for WooCommerce plugin for WordPress. Specifically, versions 8.6.5 through 8.7.5 are vulnerable to unauthorized data modification. This vulnerability stems from a missing capability check in the `cwmpUpdateOptions()` function. This flaw allows unauthenticated attackers to update arbitrary options on a WordPress site. By exploiting this, attackers can, for example, change the default registration role to "administrator" and enable user registration, effectively granting them administrative access to the compromised site.

Description
The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the cwmpUpdateOptions() function in versions 8.6.5 to 8.7.5. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
Source
security@wordfence.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@wordfence.com
CWE-862

Social media

Hype score
Not currently trending