Unauthorized Data Modification Vulnerability in Woo Slider Pro for WordPress
CVE-2025-4597
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 May 2025
What is CVE-2025-4597?
The Woo Slider Pro plugin for WordPress contains a vulnerability that allows authenticated users, including those with Subscriber-level access, to perform unauthorized data modifications. This issue arises from a missing capability check on the woo_slide_pro_delete_draft_preview AJAX action, enabling attackers to delete arbitrary posts. Sites running versions up to and including 1.12 are particularly at risk, making it essential for WordPress site administrators to apply appropriate security measures to mitigate potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Woo Slider Pro β Drag Drop Slider Builder For WooCommerce * <= 1.12
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved