PT-2025-48240 · Unknown+1 · Woocommerce+1

Abhirup Konwar

·

Published

2025-11-27

·

Updated

2025-11-27

·

CVE-2025-13441

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hide Category by User Role for WooCommerce plugin for WordPress versions prior to 2.3.1
Description The software is susceptible to a missing authorization check. Specifically, a missing capability check on the admin init hook allows unauthenticated attackers to flush the site's object cache using forged requests, potentially reducing site performance. The vulnerable function is wp cache flush().
Recommendations Update to a version newer than 2.3.1.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13441

Affected Products

Hide Category By User Role For Woocommerce
Woocommerce