Unauthorized Data Modification Vulnerability in Woo Slider Pro for WordPress
CVE-2025-4597
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 May 2025
What is CVE-2025-4597?
The Woo Slider Pro plugin for WordPress contains a vulnerability that allows authenticated users, including those with Subscriber-level access, to perform unauthorized data modifications. This issue arises from a missing capability check on the woo_slide_pro_delete_draft_preview AJAX action, enabling attackers to delete arbitrary posts. Sites running versions up to and including 1.12 are particularly at risk, making it essential for WordPress site administrators to apply appropriate security measures to mitigate potential exploits.
Affected Version(s)
Woo Slider Pro – Drag Drop Slider Builder For WooCommerce * <= 1.12