CVE-2025-3906: Integração entre Eduzz e Woocommerce 1.5.0 - 1.7.5 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wepopcoes' function in all versions up to, and including, 1.7.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit the default registration role within the plugin's registration flow to Administrator, which allows any user to create an Administrator account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3906?
The severity of CVE-2025-3906 is considered high due to the potential for unauthorized modification of data.
How do I fix CVE-2025-3906?
To fix CVE-2025-3906, update the Eduzz Integração entre Eduzz e Woocommerce plugin to version 1.7.6 or higher.
What versions are affected by CVE-2025-3906?
CVE-2025-3906 affects Eduzz Integração entre Eduzz e Woocommerce versions up to and including 1.7.5.
Who can exploit CVE-2025-3906?
Authenticated attackers with Subscriber role capabilities can exploit CVE-2025-3906 due to the missing capability check.
What type of vulnerability is CVE-2025-3906?
CVE-2025-3906 is a data modification vulnerability that arises from inadequate security checks.