
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64379 is a Missing Authorization vulnerability in the Booster for WooCommerce WordPress plugin (also known as woocommerce-jetpack) developed by Pluggabl. The flaw allows authenticated attackers with low-level privileges to exploit incorrectly configured access control security levels, gaining unauthorized access to restricted functionality or data. It affects all versions of the plugin through 7.4.0, with version 7.5.0 being the first fixed release. The vulnerability was published on November 13, 2025, and carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before granting access to certain actions or endpoints. An attacker with a low-privileged WordPress account (e.g., a subscriber or customer role) can send crafted network requests to trigger functionality that should be restricted to higher-privileged roles such as administrators. No complex preconditions or user interaction are required beyond having a valid low-privilege account on the target WordPress/WooCommerce site (Feedly, Patchstack).
Successful exploitation results in a low-level confidentiality impact, allowing an authenticated attacker to access information or functionality beyond their intended authorization level within the WooCommerce store. Integrity and availability are not directly impacted according to the CVSS scoring. The scope is limited to the affected WordPress instance, with no evidence of lateral movement potential beyond the application layer (Feedly).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-64379. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term (Feedly). Exploitation requires a low-privileged authenticated account, which somewhat limits the attack surface compared to unauthenticated vulnerabilities.
Users should update the Booster for WooCommerce plugin to version 7.5.0 or later, which addresses this missing authorization issue. Site administrators should audit user roles and permissions within their WordPress/WooCommerce installation to ensure the principle of least privilege is enforced. If an immediate update is not possible, consider temporarily deactivating the plugin or restricting site registration to trusted users to reduce exposure (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."