
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60243 is an Incorrect Privilege Assignment (CWE-266) vulnerability in the Selling Commander for WooCommerce WordPress plugin by Holest Engineering that allows unauthenticated remote attackers to escalate privileges. It affects all plugin versions up to and including 1.2.46. The vulnerability was reported on May 20, 2025, by researcher ch4r0n and published by Patchstack on June 19, 2025. It carries a CVSS v3.1 base score of 9.8 (Critical) (Patchstack).
The vulnerability is classified as CWE-266 (Incorrect Privilege Assignment), meaning the plugin incorrectly assigns or validates privilege levels during certain operations, enabling an unauthenticated network attacker to gain elevated access. Exploitation requires no authentication, no user interaction, and low attack complexity — all requests can be made directly over the network. No official patch was available at the time of publication, though Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts (Patchstack).
Successful exploitation allows an unauthenticated attacker to escalate their privileges within the WordPress/WooCommerce environment, potentially gaining administrator-level access and full control of the affected website. This results in high impact to confidentiality, integrity, and availability — attackers could exfiltrate customer and order data, modify site content or configurations, install backdoors, or disrupt site operations entirely. Given the WooCommerce context, sensitive payment and customer data may be at risk (Patchstack).
There is no public proof-of-concept exploit code and no confirmed in-the-wild exploitation reported at this time. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of exploitation in the near term. However, Patchstack classifies this as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).
No official patch from the plugin developer (Holest Engineering) was available as of the publication date; the Patchstack advisory notes "No official patch available" for versions up to and including 1.2.46. Users should upgrade to any version beyond 1.2.46 if a patched release becomes available, or use Patchstack's virtual patching rule to block exploitation in the interim. Additional recommended steps include restricting network access to the plugin, implementing additional access controls, and monitoring WordPress user accounts for unauthorized privilege changes (Patchstack).
The vulnerability was discovered by independent researcher ch4r0n and disclosed through Patchstack's Vulnerability Disclosure Program (VDP). Patchstack has flagged it as high priority, warning that privilege escalation vulnerabilities of this class are frequently leveraged in mass-exploit campaigns against WordPress sites. No significant broader media coverage or notable researcher commentary beyond the Patchstack advisory has been identified (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."