CVE-2025-64379: WordPress Booster for WooCommerce plugin <= 7.4.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booster for WooCommerce: from n/a through <= 7.4.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64379?
CVE-2025-64379 is classified as a critical vulnerability due to its potential for exploitation through incorrectly configured access control security levels.
How do I fix CVE-2025-64379?
To fix CVE-2025-64379, update the Booster for WooCommerce plugin to version 7.4.1 or later.
Who is affected by CVE-2025-64379?
CVE-2025-64379 affects users of the Booster for WooCommerce plugin on WordPress installations running version 7.4.0 or below.
What type of vulnerability is CVE-2025-64379?
CVE-2025-64379 is a missing authorization vulnerability that allows unauthorized access due to misconfigured access controls.
When was CVE-2025-64379 reported?
CVE-2025-64379 was reported in 2025, highlighting its critical importance for web security.