First published: Tue Apr 01 2025(Updated: )
Missing Authorization vulnerability in cedcommerce Ship Per Product allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Ship Per Product: from n/a through 2.1.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cedcommerce Ship Per Product | <=2.1.0 | |
WordPress Ship Per Product | <=2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31773 is classified as a high-severity vulnerability due to its potential for unauthorized access.
To fix CVE-2025-31773, update the Cedcommerce Ship Per Product plugin to version 2.1.1 or later.
CVE-2025-31773 allows accessing functionality that is not properly constrained by Access Control Lists (ACLs).
CVE-2025-31773 affects versions of Ship Per Product up to and including 2.1.0.
Yes, CVE-2025-31773 affects both CedCommerce Ship Per Product and WordPress Ship Per Product versions up to 2.1.0.