PT-2025-52546 · WordPress · Pure Wc Variation Swatches

Khaled Alenazi

·

Publicado

2025-12-20

·

Atualizado

2025-12-21

·

CVE-2025-12820

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pure WC Variation Swatches WordPress plugin versions through 1.1.7
Description The Pure WC Variation Swatches WordPress plugin does not perform authorization checks when updating its settings. This allows any authenticated user to modify these settings.
Recommendations Update the Pure WC Variation Swatches WordPress plugin to a version later than 1.1.7.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2025-12820

Produtos afetados

Pure Wc Variation Swatches