CVE-2025-64285: WordPress Premmerce Wholesale Pricing for WooCommerce plugin <= 1.1.10 - Broken Access Control vulnerability
Missing Authorization vulnerability in Premmerce Premmerce Wholesale Pricing for WooCommerce premmerce-woocommerce-wholesale-pricing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premmerce Wholesale Pricing for WooCommerce: from n/a through <= 1.1.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64285?
CVE-2025-64285 is classified as a missing authorization vulnerability that can lead to unauthorized access.
How do I fix CVE-2025-64285?
To fix CVE-2025-64285, update Premmerce Wholesale Pricing for WooCommerce to the latest version released after 1.1.10.
What software is affected by CVE-2025-64285?
CVE-2025-64285 affects Premmerce Wholesale Pricing for WooCommerce versions up to 1.1.10.
What can attackers do with CVE-2025-64285?
Attackers can exploit CVE-2025-64285 to gain incorrectly configured access to restricted features or data.
Is there a patch available for CVE-2025-64285?
Yes, Premmerce has released a patch that users must apply by updating to the latest version of the plugin.