Authorization Flaw in WC Lovers WCFM – Frontend Manager for WooCommerce
CVE-2025-54004

2.6LOW

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 December 2025

What is CVE-2025-54004?

A missing authorization vulnerability in the WC Lovers WCFM – Frontend Manager for WooCommerce can allow unauthorized access to sensitive areas of the application. This issue arises from incorrectly configured access control levels, enabling potential attackers to exploit this flaw and manipulate data without appropriate permissions. Affected versions include up to and including 6.7.21, highlighting the necessity for users to apply timely updates and review access privileges.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WCFM – Frontend Manager for WooCommerce 0 <= 6.7.24

References

CVSS V3.1

Score:
2.6
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

benzdeus | Patchstack Bug Bounty Program
.