Vulnerability Details
Basic Information
| Title | CVE-2025-4335 Woocommerce Multiple Addresses <= 1.0.7.1 - Authenticated (Subscriber+) Privilege Escalation |
|---|---|
| Type | cve |
| Published | 2025-05-07T01:43:08 |
| Last Seen | 2025-05-07T02:43:11 |
| CVSS Score | 8.8 (HIGH) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
CVE Information
| CVE IDs | CVE-2025-4335 |
|---|---|
| CWE | CWE-269 |
| Bulletin Family | cve |
Description
The Woocommerce Multiple Addresses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.7.1. This is due to insufficient restrictions on user meta…
Impact Assessment
| Base Score | 8.8 |
|---|---|
| Severity | HIGH |