CVE-2025-22673: WordPress EAN Barcode Generator <= 5.3.5 - Broken Access Control vulnerability
Missing Authorization vulnerability in WPFactory EAN for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EAN for WooCommerce: from n/a through 5.3.5.
Other sources
Missing Authorization vulnerability in WPFactory EAN for WooCommerce ean-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EAN for WooCommerce: from n/a through <= 5.3.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22673?
The severity of CVE-2025-22673 is high due to its potential to allow unauthorized access and exploitation.
How do I fix CVE-2025-22673?
To fix CVE-2025-22673, ensure that access control settings for EAN for WooCommerce are configured correctly and update to the latest version.
What versions are affected by CVE-2025-22673?
CVE-2025-22673 affects versions of EAN for WooCommerce from n/a to 5.3.5.
What type of vulnerability is CVE-2025-22673?
CVE-2025-22673 is a Missing Authorization vulnerability related to incorrectly configured access controls.
Who is the vendor for CVE-2025-22673?
The vendor for CVE-2025-22673 is WPFactory, associated with the EAN for WooCommerce plugin.