CVE-2025-48117: WordPress WooCommerce POS plugin <= 1.7.8 - Broken Access Control Vulnerability
Missing Authorization vulnerability in kilbot WooCommerce POS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooCommerce POS: from n/a through 1.7.8.
Other sources
Missing Authorization vulnerability in kilbot WooCommerce POS woocommerce-pos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce POS: from n/a through <= 1.7.8.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48117?
CVE-2025-48117 has a high severity due to its impact on access control for WooCommerce POS.
How do I fix CVE-2025-48117?
To fix CVE-2025-48117, ensure that appropriate access controls are correctly configured and consider updating to the latest version of Kilbot WooCommerce POS.
Which versions of WooCommerce POS are affected by CVE-2025-48117?
CVE-2025-48117 affects all versions of Kilbot WooCommerce POS from n/a up to and including version 1.7.8.
What type of vulnerability is CVE-2025-48117?
CVE-2025-48117 is a missing authorization vulnerability that allows exploitation due to incorrectly configured access control security levels.
Who is affected by CVE-2025-48117?
Any user of Kilbot WooCommerce POS versions n/a through 1.7.8 may be affected by CVE-2025-48117.