Privilege Escalation Vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce
CVE-2025-48129
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 June 2025
What is CVE-2025-48129?
The Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce β Light is susceptible to an Incorrect Privilege Assignment vulnerability, which allows attackers to escalate privileges. This weakness can potentially enable unauthorized users to gain elevated access and perform actions that should be restricted. The issue affects all versions of the product from its initial release until version 2.4.37, necessitating prompt updates to protect against exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Spreadsheet Price Changer for WooCommerce and WP E-commerce β Light <= 2.4.37
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved