PT-2026-1896 · Wofficeio · Wofficeio Woffice Core

Rafie Muhammad

·

Published

2026-01-08

·

Updated

2026-01-08

·

CVE-2025-67919

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions WofficeIO Woffice Core versions prior to 5.4.30
Description An authorization bypass exists due to incorrectly configured access control security levels. This allows exploitation through a user-controlled key. The issue affects the woffice-core component.
Recommendations Update WofficeIO Woffice Core to a version later than 5.4.30.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-67919

Affected Products

Wofficeio Woffice Core