
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67909 is an Insecure Direct Object Reference (IDOR) / Authorization Bypass Through User-Controlled Key vulnerability in the WP Swings "Membership For WooCommerce" WordPress plugin. It affects all versions up to and including 3.0.3, and was reported by researcher timomangcut on April 30, 2025, then publicly disclosed on December 24, 2025. The vulnerability was assigned a CVSS v3.1 base score of 8.1 (High) by NVD, while Patchstack rates it 7.5 (High) (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), corresponding to OWASP Top 10 category A1: Broken Access Control. The flaw arises from incorrectly configured access control security levels within the plugin, allowing an attacker to manipulate user-controlled object references (e.g., membership record IDs) to access or modify resources belonging to other users without proper authorization checks. Exploitation requires only low-level authenticated access per NVD's CVSS vector, though Patchstack notes the required privilege as "Unauthenticated," suggesting the access control gap may be reachable without authentication in some contexts (Patchstack, Red Hat CVE).
Successful exploitation can result in high confidentiality and high integrity impact, with no availability impact. An attacker can access sensitive user membership data, modify or manipulate membership records, and bypass intended access controls within the WooCommerce environment. This could expose personally identifiable information (PII) of members, allow unauthorized privilege escalation within the membership system, and enable mass exploitation across WordPress sites running the vulnerable plugin (Patchstack).
There is no public proof-of-concept exploit code and no confirmed in-the-wild exploitation reported at this time. The EPSS score is approximately 0.028% (0.000280), indicating a low current probability of exploitation. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority and notes that IDOR vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack, Red Hat CVE).
Update the "Membership For WooCommerce" plugin to version 3.0.4 or later, which contains the patch for this vulnerability. Patchstack has also issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until the plugin is updated. Additionally, administrators should review user roles and permissions, implement the principle of least privilege, and monitor for unauthorized access or suspicious membership record activity (Patchstack).
Patchstack, which coordinated the disclosure, classifies this as a high-priority vulnerability and warns that IDOR vulnerabilities of this class are frequently leveraged in mass-exploit campaigns targeting WordPress plugins regardless of site popularity or traffic. The vulnerability was reported through Patchstack's VDP program by researcher timomangcut and disclosed publicly on December 24, 2025. No significant broader media coverage or notable researcher commentary beyond Patchstack's advisory has been identified (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."