CVE-2025-64267: WordPress WooCommerce Ultimate Points And Rewards plugin <= 2.10.2 - Sensitive Data Exposure vulnerability
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPSwings WooCommerce Ultimate Points And Rewards woocommerce-ultimate-points-and-rewards allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce Ultimate Points And Rewards: from n/a through <= 2.10.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64267?
CVE-2025-64267 is classified as a moderate severity vulnerability that allows unauthorized retrieval of sensitive data.
How do I fix CVE-2025-64267?
To fix CVE-2025-64267, update the WooCommerce Ultimate Points And Rewards plugin to the latest version beyond 2.10.2.
What versions of WooCommerce Ultimate Points And Rewards are affected by CVE-2025-64267?
CVE-2025-64267 affects versions of WooCommerce Ultimate Points And Rewards up to and including 2.10.2.
What type of data is exposed in CVE-2025-64267?
CVE-2025-64267 exposes sensitive system information that can be retrieved by unauthorized users.
Who is impacted by CVE-2025-64267?
Users of the WooCommerce Ultimate Points And Rewards plugin, specifically those using versions up to 2.10.2, are impacted by CVE-2025-64267.