CVE-2025-47472: WordPress Music Player for WooCommerce plugin <= 1.5.1 - Broken Access Control Vulnerability
Missing Authorization vulnerability in codepeople Music Player for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Music Player for WooCommerce: from n/a through 1.5.1.
Other sources
Missing Authorization vulnerability in codepeople Music Player for WooCommerce music-player-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Music Player for WooCommerce: from n/a through <= 1.5.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47472?
CVE-2025-47472 is classified as a Missing Authorization vulnerability affecting the Music Player for WooCommerce.
How do I fix CVE-2025-47472?
To fix CVE-2025-47472, you should update the Music Player for WooCommerce to the latest version beyond 1.5.1.
What versions are affected by CVE-2025-47472?
CVE-2025-47472 affects all versions of Music Player for WooCommerce from its initial release up to version 1.5.1.
What type of vulnerability is CVE-2025-47472?
CVE-2025-47472 is categorized as a Broken Access Control vulnerability.
Can CVE-2025-47472 be exploited remotely?
Yes, CVE-2025-47472 can be exploited remotely due to incorrectly configured access control security levels.