First published: Tue Apr 01 2025(Updated: )
Missing Authorization vulnerability in Ship Depot ShipDepot for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ShipDepot for WooCommerce: from n/a through 1.2.19.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
ShipDepot for WooCommerce | <=1.2.19 | |
ShipDepot for WooCommerce | <=1.2.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31866 is classified as a missing authorization vulnerability that can result in unauthorized access due to incorrectly configured access control.
To fix CVE-2025-31866, ensure that access control settings are properly configured and upgrade ShipDepot for WooCommerce to the latest version beyond 1.2.19.
CVE-2025-31866 affects all versions of ShipDepot for WooCommerce up to and including 1.2.19.
Yes, CVE-2025-31866 can potentially lead to data breaches if access controls are improperly managed.
CVE-2025-31866 reflects a common issue found in many applications, particularly those with misconfigured access controls.