
Cloud Vulnerability DB
A community-led vulnerabilities database
The Appy Pie Connect for WooCommerce plugin for WordPress contains a Privilege Escalation vulnerability (CVE-2025-9286) discovered in all versions up to and including 1.1.2. The vulnerability was disclosed on October 2, 2025, and affects the reset_user_password() REST handler functionality (NVD, Wordfence).
The vulnerability stems from missing authorization checks within the reset_user_password() REST handler. This security flaw has been assigned a CVSS v3.1 score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a critical severity level. The vulnerability is classified under CWE-620 (Unverified Password Change) (NVD).
The vulnerability allows unauthenticated attackers to reset the password of arbitrary users, including administrators. This can lead to complete administrative access to the WordPress installation, potentially compromising the entire website (NVD).
The plugin has been temporarily closed as of October 1, 2025, pending a full security review. Users are advised to remove the plugin until a patched version is available (WordPress Plugin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."