CVE-2025-10173: ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.3 - Insufficient Authorization to Authenticated (Editor+) Settings Update
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the postsave() function in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with Editor-level access and above, to update the plugin's settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10173?
The severity of CVE-2025-10173 is considered critical due to the risk of unauthorized access.
What versions are affected by CVE-2025-10173?
All versions of the ShopEngine Elementor WooCommerce Builder Addon up to and including 4.8.3 are affected by CVE-2025-10173.
How do I fix CVE-2025-10173?
To fix CVE-2025-10173, upgrade the ShopEngine Elementor WooCommerce Builder Addon to the latest version available.
What is the risk associated with CVE-2025-10173?
The risk associated with CVE-2025-10173 is that unauthorized users may gain access to sensitive WooCommerce functionality.
Who is affected by CVE-2025-10173?
Users of the ShopEngine Elementor WooCommerce Builder Addon who are running versions 4.8.3 or earlier are affected by CVE-2025-10173.