CVE-2025-54692: WordPress Membership For WooCommerce Plugin <= 2.9.0 - Broken Access Control Vulnerability
Missing Authorization vulnerability in WP Swings Membership For WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Membership For WooCommerce: from n/a through 2.9.0.
Other sources
Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Membership For WooCommerce: from n/a through <= 2.9.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54692?
CVE-2025-54692 is classified as a missing authorization vulnerability, which can lead to unauthorized access to functionality.
How do I fix CVE-2025-54692?
To fix CVE-2025-54692, update the WP Swings Membership For WooCommerce plugin to a version beyond 2.9.0.
What versions are affected by CVE-2025-54692?
CVE-2025-54692 affects all versions of WP Swings Membership For WooCommerce up to and including version 2.9.0.
What type of vulnerability is CVE-2025-54692?
CVE-2025-54692 is a broken access control vulnerability that allows access to functions not properly constrained by ACLs.
Which software is impacted by CVE-2025-54692?
CVE-2025-54692 impacts the WP Swings Membership For WooCommerce and the WordPress Membership For WooCommerce Plugin.