CVE-2025-23991: WordPress Product Size Charts Plugin for WooCommerce plugin <= 2.4.5 - Broken Access Control vulnerability
Published Jan 24, 2025
·Updated
Missing Authorization vulnerability in Dotstore Product Size Charts Plugin for WooCommerce woo-advanced-product-size-chart.This issue affects Product Size Charts Plugin for WooCommerce: from n/a through <= 2.4.5.
Affected Software
1 affected component
Dotstore Product Size Charts Plugin for WooCommerce (woo-advanced-product-size-chart)<=2.4.5
Event History
Jan 24, 2025
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-23991?
CVE-2025-23991 is classified as a missing authorization vulnerability.
2
How do I fix CVE-2025-23991?
To fix CVE-2025-23991, update the Product Size Charts Plugin for WooCommerce to version 2.4.6 or later.
3
What versions of theProduct Size Charts Plugin for WooCommerce are affected by CVE-2025-23991?
CVE-2025-23991 affects the Product Size Charts Plugin for WooCommerce versions up to and including 2.4.5.
4
What type of vulnerability is CVE-2025-23991?
CVE-2025-23991 is a broken access control vulnerability that allows unauthorized access.
5
Who is the vendor for CVE-2025-23991?
The vendor for CVE-2025-23991 is TheDotstore, which develops the Product Size Charts Plugin for WooCommerce.