PT-2026-43413 · Woocommerce · Envato Affiliater

Published

2026-05-26

·

Updated

2026-06-04

·

CVE-2025-14361

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Woocommerce Envato Affiliates versions prior to 1.2.2
Description A missing authorization issue allows access to functionality that is not properly constrained by Access Control Lists (ACLs), which are sets of rules that define which users or system processes are granted access to specific objects.
Recommendations Update to version 1.2.2 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14361

Affected Products

Envato Affiliater