CVE-2025-66089: WordPress Product Feed for WooCommerce plugin <= 2.3.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Feed for WooCommerce: from n/a through <= 2.3.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66089?
CVE-2025-66089 has been identified as a critical severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-66089?
To fix CVE-2025-66089, upgrade the WebToffee Product Feed for WooCommerce to version 2.3.2 or later.
What causes CVE-2025-66089?
CVE-2025-66089 is caused by improperly configured access control security levels in the affected plugin.
Which versions are affected by CVE-2025-66089?
CVE-2025-66089 affects WebToffee Product Feed for WooCommerce versions up to and including 2.3.1.
Can CVE-2025-66089 lead to data breaches?
Yes, CVE-2025-66089 can potentially lead to data breaches by allowing unauthorized users to access sensitive information.