
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69381 is a Missing Authorization (Broken Access Control) vulnerability in the WooCommerce Bulk Product Editor WordPress plugin by vanquish. It affects all versions up to and including 3.0, allowing low-privileged authenticated attackers to exploit incorrectly configured access control security levels. The vulnerability was reported on November 24, 2025, and published on February 9–20, 2026. It carries a CVSS v3.1 base score of 7.1 (High) (Patchstack, Feedly).
The root cause is CWE-862 (Missing Authorization) — the plugin fails to perform adequate authorization checks on certain functions, allowing users with low privileges (e.g., Subscriber level) to perform actions that should be restricted to higher-privileged roles (Patchstack). The attack vector is network-based, requires low privileges and no user interaction, and has low attack complexity. The missing nonce token or capability check in the plugin's bulk product editing functionality enables a subscriber-level user to trigger privileged operations such as modifying or deleting WooCommerce product data (Feedly). No public proof-of-concept code has been identified at this time.
Successful exploitation allows a low-privileged authenticated attacker to modify WooCommerce product data (integrity impact) and potentially cause high availability impact — for example, by bulk-deleting or corrupting product listings, which could disrupt store operations (Patchstack, Feedly). Confidentiality impact is rated as none. The scope is limited to the affected WordPress/WooCommerce installation, but disruption to product catalogs could have significant business consequences for e-commerce sites.
No confirmed in-the-wild exploitation has been reported for CVE-2025-69381. The EPSS score is approximately 0.017% (0.000170), indicating a low current probability of exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that broken access control vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress plugins at scale, regardless of site popularity (Patchstack).
woocommerce-quick-product-editor) version ≤ 3.0 using tools like WPScan, Shodan, or by checking the plugin's readme.txt file at https://target.com/wp-content/plugins/woocommerce-quick-product-editor/readme.txt.wp-admin/admin-ajax.php with plugin-specific action parameters from Subscriber-level user accounts; unexpected bulk product update or delete events in WooCommerce order/product logs.As of the publication date, no official patch from the plugin developer is available for WooCommerce Bulk Product Editor version 3.0 (Patchstack). Recommended actions include: (1) deactivating and removing the plugin until a patched version is released; (2) using Patchstack's virtual patching/mitigation rule, which blocks exploit attempts without requiring a code-level fix; (3) restricting user registration on WooCommerce stores to limit the pool of potential attackers with low-privileged accounts. Site owners should monitor the WordPress plugin repository and the vendor's changelog for an updated release.
Patchstack, which discovered and disclosed the vulnerability (credited to researcher Phat RiO), classifies it as medium priority and warns that broken access control issues of this type are frequently leveraged in mass-exploit campaigns against WordPress sites (Patchstack). No significant broader media coverage or notable social media discussion has been identified for this specific CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."