PT-2025-13607 · WordPress · Checkout Mestres Wp

Kenneth Dunn

·

Published

2025-03-29

·

Updated

2025-04-03

·

CVE-2025-2266

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Checkout Mestres do WP for WooCommerce plugin for WordPress versions 8.6.5 through 8.7.5
Description The issue allows unauthorized modification of data, leading to privilege escalation due to a missing capability check on the cwmpUpdateOptions() function. This enables unauthenticated attackers to update arbitrary options on the WordPress site, potentially updating the default role for registration to administrator and enabling user registration for attackers to gain administrative user access.
Recommendations For versions 8.6.5 through 8.7.5, consider disabling the cwmpUpdateOptions() function until a patch is available to prevent unauthorized updates to site options. Restrict access to user registration and ensure that default roles are set appropriately to minimize the risk of exploitation. Update to a version that includes a fix for this issue when available.

Fix

LPE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-2266

Affected Products

Checkout Mestres Wp