CVE-2025-7827: Ni WooCommerce Customer Product Report <= 1.2.4 - Missing Authorization to Authenticated (Subscriber+) Settings Update
The Ni WooCommerce Customer Product Report plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the niwoocpraction() function in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update plugin settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7827?
CVE-2025-7827 is classified as a medium severity vulnerability due to the risk of unauthorized data modification.
How do I fix CVE-2025-7827?
To fix CVE-2025-7827, update the Ni WooCommerce Customer Product Report plugin to version 1.2.5 or later, which includes the necessary capability checks.
Who is affected by CVE-2025-7827?
All users of the Ni WooCommerce Customer Product Report plugin for WordPress, version 1.2.4 and earlier, are affected by CVE-2025-7827.
What types of attacks can be performed due to CVE-2025-7827?
Due to CVE-2025-7827, authenticated attackers can modify customer product reports without proper authorization.
Is there a patch available for CVE-2025-7827?
Yes, a patch is available by upgrading to version 1.2.5 or later of the Ni WooCommerce Customer Product Report plugin.