First published: Thu Mar 27 2025(Updated: )
Missing Authorization vulnerability in WPClever WPC Smart Upsell Funnel for WooCommerce allows Privilege Escalation. This issue affects WPC Smart Upsell Funnel for WooCommerce: from n/a through 3.0.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPClever WPC Smart Upsell Funnel for WooCommerce | <=3.0.4 | |
WPClever WPC Smart Upsell Funnel for WooCommerce | <=3.0.4 |
Update the WordPress WPC Smart Upsell Funnel for WooCommerce plugin to the latest available version (at least 3.0.5).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-30772 is considered critical due to its exploitation potential for privilege escalation.
To fix CVE-2025-30772, update the WPC Smart Upsell Funnel for WooCommerce plugin to version 3.0.5 or later.
CVE-2025-30772 affects WPC Smart Upsell Funnel for WooCommerce versions up to and including 3.0.4.
CVE-2025-30772 is classified as a Missing Authorization vulnerability.
Yes, CVE-2025-30772 can be exploited remotely, allowing attackers to escalate privileges.