First published: Tue Apr 01 2025(Updated: )
Missing Authorization vulnerability in Anzar Ahmed Ni WooCommerce Product Enquiry allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Ni WooCommerce Product Enquiry: from n/a through 4.1.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WooCommerce Product Enquiry | <=4.1.8 | |
WooCommerce Product Enquiry | <=4.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31580 is classified as a missing authorization vulnerability, which could lead to unauthorized access to certain functionalities.
To fix CVE-2025-31580, update the Ni WooCommerce Product Enquiry plugin to the latest version that addresses the access control issues.
CVE-2025-31580 affects Ni WooCommerce Product Enquiry versions up to and including 4.1.8.
CVE-2025-31580 is a broken access control vulnerability that allows access to functionality not properly constrained by access control lists (ACLs).
Users of the Ni WooCommerce Product Enquiry plugin on WordPress who are running version 4.1.8 or earlier are impacted by CVE-2025-31580.