First published: Thu Mar 27 2025(Updated: )
Missing Authorization vulnerability in WPFactory EAN for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EAN for WooCommerce: from n/a through 5.3.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPFactory EAN Barcode Generator | >=5.3.5 | |
WPFactory EAN Barcode Generator | <=5.3.5 |
Update the WordPress EAN for WooCommerce wordpress plugin to the latest available version (at least 5.4.0).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-22673 is high due to its potential to allow unauthorized access and exploitation.
To fix CVE-2025-22673, ensure that access control settings for EAN for WooCommerce are configured correctly and update to the latest version.
CVE-2025-22673 affects versions of EAN for WooCommerce from n/a to 5.3.5.
CVE-2025-22673 is a Missing Authorization vulnerability related to incorrectly configured access controls.
The vendor for CVE-2025-22673 is WPFactory, associated with the EAN for WooCommerce plugin.