Unauthorized Data Modification Vulnerability in Woo Slider Pro for WordPress
CVE-2025-4597

6.5MEDIUM

What is CVE-2025-4597?

The Woo Slider Pro plugin for WordPress contains a vulnerability that allows authenticated users, including those with Subscriber-level access, to perform unauthorized data modifications. This issue arises from a missing capability check on the woo_slide_pro_delete_draft_preview AJAX action, enabling attackers to delete arbitrary posts. Sites running versions up to and including 1.12 are particularly at risk, making it essential for WordPress site administrators to apply appropriate security measures to mitigate potential exploits.

Affected Version(s)

Woo Slider Pro – Drag Drop Slider Builder For WooCommerce * <= 1.12

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Cheng Liu
.
CVE-2025-4597 : Unauthorized Data Modification Vulnerability in Woo Slider Pro for WordPress