PT-2026-2834 · Perfitdev · Perfit Woocommerce

Abhirup Konwar

·

Published

2026-01-14

·

Updated

2026-01-14

·

CVE-2025-14173

CVSS v3.1
5.3
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The Perfit WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.1. This is due to missing authorization checks on the
logout
function called via the
actions
function hooked to
admin init
. This makes it possible for unauthenticated attackers to delete arbitrary plugin settings via the
action
parameter.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14173

Affected Products

Perfit Woocommerce