CVE-2025-39571: WordPress WowStore plugin <= 4.2.4 - Broken Access Control Vulnerability
Missing Authorization vulnerability in WPXPO WowStore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WowStore: from n/a through 4.2.4.
Other sources
Missing Authorization vulnerability in WPXPO WowStore product-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowStore: from n/a through <= 4.2.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39571?
CVE-2025-39571 is classified as a high severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2025-39571?
To fix CVE-2025-39571, update the WPXPO WowStore plugin to version 4.2.5 or later.
What type of vulnerability is CVE-2025-39571?
CVE-2025-39571 is a missing authorization vulnerability that allows exploitation through incorrectly configured access control.
Which versions of WowStore are affected by CVE-2025-39571?
CVE-2025-39571 affects all versions of WPXPO WowStore up to and including 4.2.4.
What are the risks associated with CVE-2025-39571?
The risks associated with CVE-2025-39571 include unauthorized access to sensitive data and potential data manipulation.