CVE-2025-5813: Amazon Products to WooCommerce <= 1.2.7 - Missing Authorization to Unauthenticated Arbitrary Product Creation
The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcta2wgetamazonproductcallback() function in all versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to create new produces.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5813?
CVE-2025-5813 is considered a critical vulnerability due to the risk of unauthorized data modification.
How do I fix CVE-2025-5813?
To fix CVE-2025-5813, update the Amazon Products to WooCommerce plugin to version 1.2.8 or later.
What versions of Amazon Products to WooCommerce are affected by CVE-2025-5813?
All versions of Amazon Products to WooCommerce up to and including 1.2.7 are affected by CVE-2025-5813.
Who can exploit CVE-2025-5813?
CVE-2025-5813 can be exploited by unauthenticated users due to the lack of capability checks.
What type of attack is possible with CVE-2025-5813?
CVE-2025-5813 allows attackers to modify product data without authentication, potentially leading to data integrity issues.