PT-2025-46802 · WordPress · Woocommerce Ultimate Points/Rewards

Published

2025-11-13

·

Updated

2025-11-13

·

CVE-2025-64267

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WooCommerce Ultimate Points And Rewards versions through 2.10.2
Description The WooCommerce Ultimate Points And Rewards plugin contains a flaw that allows the retrieval of embedded sensitive data. This issue results in an exposure of sensitive system information to an unauthorized control sphere.
Recommendations Update WooCommerce Ultimate Points And Rewards to a version later than 2.10.2.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-64267

Affected Products

Woocommerce Ultimate Points/Rewards