CVE-2025-66069: WordPress PPOM for WooCommerce plugin <= 33.0.16 - Broken Access Control vulnerability
Missing Authorization vulnerability in Themeisle PPOM for WooCommerce woocommerce-product-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PPOM for WooCommerce: from n/a through <= 33.0.16.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66069?
CVE-2025-66069 is categorized as a high severity vulnerability due to its potential to exploit improperly configured access control settings.
How do I fix CVE-2025-66069?
To fix CVE-2025-66069, update the PPOM for WooCommerce plugin to version 33.0.17 or later, which contains the necessary security patches.
What are the risks associated with CVE-2025-66069?
The risks associated with CVE-2025-66069 include unauthorized access to sensitive data and potential exploitation of incorrectly configured access controls.
Which versions of PPOM for WooCommerce are affected by CVE-2025-66069?
CVE-2025-66069 affects PPOM for WooCommerce versions up to and including 33.0.16.
Can I still use my current theme with CVE-2025-66069?
You can use your current theme, but it is critical to update the PPOM for WooCommerce plugin to eliminate the risks posed by CVE-2025-66069.