CVE-2025-54697: WordPress Kadence WooCommerce Email Designer Plugin <= 1.5.16 - Privilege Escalation Vulnerability
Incorrect Privilege Assignment vulnerability in Ben Ritner - Kadence WP Kadence WooCommerce Email Designer allows Privilege Escalation. This issue affects Kadence WooCommerce Email Designer: from n/a through 1.5.16.
Other sources
Incorrect Privilege Assignment vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-woocommerce-email-designer allows Privilege Escalation.This issue affects Kadence WooCommerce Email Designer: from n/a through <= 1.5.16.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54697?
CVE-2025-54697 is classified as a privilege escalation vulnerability.
How does CVE-2025-54697 impact the Kadence WooCommerce Email Designer?
CVE-2025-54697 allows unauthorized users to gain elevated privileges within the Kadence WooCommerce Email Designer.
How do I fix CVE-2025-54697?
To fix CVE-2025-54697, users should update the Kadence WooCommerce Email Designer to the latest version beyond 1.5.16.
Who is affected by CVE-2025-54697?
CVE-2025-54697 affects all versions of the Kadence WooCommerce Email Designer up to and including version 1.5.16.
What should I do if I can't update my plugin due to CVE-2025-54697?
If you are unable to update your plugin due to CVE-2025-54697, it is recommended to restrict access to the plugin until a safe upgrade can be implemented.