PT-2025-46802 · WordPress · Woocommerce Ultimate Points/Rewards

CVE-2025-64267

·

Published

2025-11-13

·

Updated

2025-11-13

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WooCommerce Ultimate Points And Rewards versions through 2.10.2
Description The WooCommerce Ultimate Points And Rewards plugin contains a flaw that allows the retrieval of embedded sensitive data. This issue results in an exposure of sensitive system information to an unauthorized control sphere.
Recommendations Update WooCommerce Ultimate Points And Rewards to a version later than 2.10.2.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64267

Affected Products

Woocommerce Ultimate Points/Rewards