PT-2025-47757 · WordPress · Webtoffee Product Feed For Woocommerce

Published

2025-11-21

·

Updated

2025-11-21

·

CVE-2025-66089

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WebToffee Product Feed for WooCommerce versions through 2.3.1
Description An issue exists in WebToffee Product Feed for WooCommerce related to incorrectly configured access control security levels, potentially allowing unauthorized access. The issue involves a missing authorization check.
Recommendations Update WebToffee Product Feed for WooCommerce to a version later than 2.3.1.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-66089

Affected Products

Webtoffee Product Feed For Woocommerce