CVE-2025-4335: Woocommerce Multiple Addresses <= 1.0.7.1 - Authenticated (Subscriber+) Privilege Escalation
The Woocommerce Multiple Addresses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.7.1. This is due to insufficient restrictions on user meta that can be updated through the savemultipleshippingaddresses() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4335?
CVE-2025-4335 is categorized as a Privilege Escalation vulnerability, which can potentially allow unauthorized users to gain elevated permissions.
How do I fix CVE-2025-4335?
To fix CVE-2025-4335, you should update the Woocommerce Multiple Addresses plugin to version 1.0.7.2 or later.
What versions are affected by CVE-2025-4335?
CVE-2025-4335 affects all versions of the Woocommerce Multiple Addresses plugin up to and including 1.0.7.1.
What is the impact of CVE-2025-4335 on users?
The impact of CVE-2025-4335 allows users to manipulate user meta data, potentially leading to unauthorized access and privilege escalation.
Is CVE-2025-4335 easy to exploit?
The CVE-2025-4335 vulnerability is relatively easy to exploit due to insufficient access controls on the save_multiple_shipping_addresses() function.