PT-2025-23279 · WordPress · Woo Slider Pro

Cheng Liu

·

Published

2025-05-30

·

Updated

2025-05-30

·

CVE-2025-4597

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress versions up to, and including, 1.12
Description The issue allows authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts due to a missing capability check on the woo slide pro delete draft preview AJAX action.
Recommendations For versions up to, and including, 1.12, update to a version that includes a fix for the missing capability check on the woo slide pro delete draft preview AJAX action. As a temporary workaround, consider restricting access to the woo slide pro delete draft preview AJAX action to prevent unauthorized data modification.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-4597

Affected Products

Woo Slider Pro