PT-2026-1896 · Wofficeio · Wofficeio Woffice Core

·

CVE-2025-67919

·

Published

2026-01-08

·

Updated

2026-01-08

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions WofficeIO Woffice Core versions prior to 5.4.30
Description An authorization bypass exists due to incorrectly configured access control security levels. This allows exploitation through a user-controlled key. The issue affects the woffice-core component.
Recommendations Update WofficeIO Woffice Core to a version later than 5.4.30.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67919

Affected Products

Wofficeio Woffice Core