CVE-2025-49287: WordPress Product Feed for WooCommerce plugin <= 2.2.8 - Broken Access Control Vulnerability
Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Feed for WooCommerce: from n/a through 2.2.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49287?
CVE-2025-49287 has not been publicly assigned a severity rating, but it is classified as a Missing Authorization vulnerability.
How do I fix CVE-2025-49287?
To fix CVE-2025-49287, update the WebToffee Product Feed for WooCommerce plugin to version 2.2.9 or later.
What systems are affected by CVE-2025-49287?
CVE-2025-49287 affects WebToffee Product Feed for WooCommerce versions up to 2.2.8.
What type of vulnerability is CVE-2025-49287?
CVE-2025-49287 is categorized as a Missing Authorization vulnerability due to incorrectly configured access control.
What can attackers do with CVE-2025-49287?
Attackers can exploit CVE-2025-49287 to gain unauthorized access to restricted functionalities within the WebToffee Product Feed for WooCommerce.