CVE-2025-30772: WordPress WPC Smart Upsell Funnel for WooCommerce plugin <= 3.0.4 - Arbitrary Option Update to Privilege Escalation vulnerability
Missing Authorization vulnerability in WPClever WPC Smart Upsell Funnel for WooCommerce wpc-smart-upsell-funnel allows Privilege Escalation.This issue affects WPC Smart Upsell Funnel for WooCommerce: from n/a through <= 3.0.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WPClever WPC Smart Upsell Funnel for WooCommerce (wpc-smart-upsell-funnel)to a version that resolves this vulnerability.Fixed in 3.0.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30772?
The severity of CVE-2025-30772 is considered critical due to its exploitation potential for privilege escalation.
How do I fix CVE-2025-30772?
To fix CVE-2025-30772, update the WPC Smart Upsell Funnel for WooCommerce plugin to version 3.0.5 or later.
What software is affected by CVE-2025-30772?
CVE-2025-30772 affects WPC Smart Upsell Funnel for WooCommerce versions up to and including 3.0.4.
What type of vulnerability is CVE-2025-30772?
CVE-2025-30772 is classified as a Missing Authorization vulnerability.
Can CVE-2025-30772 be exploited remotely?
Yes, CVE-2025-30772 can be exploited remotely, allowing attackers to escalate privileges.