
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69378 is an Incorrect Privilege Assignment vulnerability (CWE-266) in the Product Filter for WooCommerce WordPress plugin by XforWooCommerce, allowing authenticated attackers with high privileges (e.g., Shop Manager role) to escalate their privileges. It affects all plugin versions up to and including 9.1.2, with version 9.1.3 containing the fix. The vulnerability was reported on November 23, 2025, and published by Patchstack on February 5, 2026. It carries a CVSS v3.1 base score of 7.2 (High) (Patchstack).
The root cause is classified as CWE-266 (Incorrect Privilege Assignment), meaning the plugin incorrectly assigns or validates privilege levels during certain operations, allowing a lower-privileged authenticated user (such as a Shop Manager) to gain higher-level access than intended. The attack vector is network-based, requires no user interaction, and has low attack complexity, though it does require an existing high-privilege (but not administrator-level) account to initiate exploitation. No public proof-of-concept code has been identified at this time. The vulnerability was discovered and credited to researcher Phat RiO (Patchstack).
Successful exploitation allows an attacker with a Shop Manager or Developer-level WordPress account to escalate their privileges, potentially gaining full administrative control over the affected WordPress/WooCommerce site. This could result in complete compromise of confidentiality, integrity, and availability of the site — including unauthorized access to customer data, order information, and the ability to install malicious plugins or backdoors. The scope is limited to the affected WordPress instance, but a fully compromised site could serve as a pivot point for further attacks against site visitors or connected systems (Patchstack).
No public exploit code or active in-the-wild exploitation has been confirmed for CVE-2025-69378 at this time. The EPSS score is very low at approximately 0.017%, indicating a low near-term probability of exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).
wp-content/plugins/; new PHP files with obfuscated code or web shell characteristics.wp_users/wp_usermeta tables without a legitimate administrative action; unexpected changes to user roles in wp_usermeta./wp-admin/) originating from accounts that should not have administrative access.The vendor has released version 9.1.3 of the Product Filter for WooCommerce plugin, which resolves this vulnerability. Site administrators should update the plugin immediately via the WordPress dashboard or manually. Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated. As an additional precaution, review WordPress user accounts with Shop Manager or Developer roles and ensure only trusted individuals hold these roles (Patchstack).
Patchstack, which coordinated disclosure after the vulnerability was reported by researcher Phat RiO on November 23, 2025, classified this as medium priority and noted that privilege escalation vulnerabilities of this type are frequently leveraged in mass WordPress exploit campaigns. Wordfence also referenced the vulnerability in their weekly WordPress vulnerability report for the period of February 2–8, 2026 (Wordfence). No significant broader media coverage or notable social media discussion has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."