Missing Authorization Vulnerability in Arshid WooCommerce Quick View Plugin
CVE-2025-24705

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 January 2025

What is CVE-2025-24705?

A vulnerability exists in the Arshid WooCommerce Quick View plugin that allows for improperly configured access control security levels. This issue enables unauthorized users to gain access to sensitive functionalities within the plugin. It affects all versions from n/a through 1.1.1, potentially exposing private data. Proper security measures should be applied to mitigate the risk associated with this vulnerability.

Affected Version(s)

WooCommerce Quick View <= 1.1.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.
CVE-2025-24705 : Missing Authorization Vulnerability in Arshid WooCommerce Quick View Plugin