Privilege Escalation Vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce
CVE-2025-48129
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 June 2025
What is CVE-2025-48129?
The Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light is susceptible to an Incorrect Privilege Assignment vulnerability, which allows attackers to escalate privileges. This weakness can potentially enable unauthorized users to gain elevated access and perform actions that should be restricted. The issue affects all versions of the product from its initial release until version 2.4.37, necessitating prompt updates to protect against exploitation.
Affected Version(s)
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37