CVE-2025-67599: WordPress WebToffee eCommerce Marketing Automation plugin <= 2.1.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in WebToffee WebToffee eCommerce Marketing Automation decorator-woocommerce-email-customizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebToffee eCommerce Marketing Automation: from n/a through <= 2.1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67599?
CVE-2025-67599 is considered a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-67599?
To fix CVE-2025-67599, update the WebToffee eCommerce Marketing Automation plugin to the latest version that addresses access control issues.
What systems are affected by CVE-2025-67599?
CVE-2025-67599 affects versions of the WebToffee eCommerce Marketing Automation plugin up to and including version 2.1.1.
What type of vulnerability is CVE-2025-67599?
CVE-2025-67599 is a missing authorization vulnerability that arises from incorrect access control configurations.
Who is the vendor for CVE-2025-67599?
The vendor for CVE-2025-67599 is WebToffee, specifically for their WebToffee eCommerce Marketing Automation product.