4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
Description
Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Feed for WooCommerce: from n/a through <= 2.3.1.
Basic Information
ID
CVE-2025-66089
Source
Patchstack
Published
Nov 21, 2025 at 12:29
Modified
Nov 21, 2025 at 16:37
Affected Product
Vendor
WebToffee
Product
Product Feed for WooCommerce
Version
n/a
Affected Versions
WebToffee Product Feed for WooCommerce n/a