CVE-2025-67566: WordPress Woffice Core plugin <= 5.4.30 - Broken Access Control vulnerability
Missing Authorization vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woffice Core: from n/a through <= 5.4.30.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67566?
The severity of CVE-2025-67566 is classified as high due to the potential for unauthorized access resulting from missing authorization checks.
How do I fix CVE-2025-67566?
To fix CVE-2025-67566, upgrade Woffice Core to version 5.4.31 or later, which includes patches for the vulnerability.
What versions of Woffice Core are affected by CVE-2025-67566?
CVE-2025-67566 affects Woffice Core versions from n/a through 5.4.30.
What type of vulnerability is CVE-2025-67566?
CVE-2025-67566 is a Missing Authorization vulnerability that allows exploitation through incorrectly configured access control security levels.
Is it safe to continue using versions of Woffice Core up to 5.4.30 after CVE-2025-67566 has been identified?
It is not safe to continue using versions of Woffice Core up to 5.4.30 as they are vulnerable to unauthorized access.