Authorization Flaw in WC Lovers WCFM – Frontend Manager for WooCommerce
CVE-2025-54004
2.7LOW
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 December 2025
What is CVE-2025-54004?
A missing authorization vulnerability in the WC Lovers WCFM – Frontend Manager for WooCommerce can allow unauthorized access to sensitive areas of the application. This issue arises from incorrectly configured access control levels, enabling potential attackers to exploit this flaw and manipulate data without appropriate permissions. Affected versions include up to and including 6.7.21, highlighting the necessity for users to apply timely updates and review access privileges.
Affected Version(s)
WCFM – Frontend Manager for WooCommerce 0 <= 6.7.24