Data Modification Vulnerability in Amazon Products to WooCommerce Plugin by WordPress
CVE-2025-5813
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 June 2025
What is CVE-2025-5813?
The Amazon Products to WooCommerce plugin for WordPress contains a security flaw that allows unauthorized data modification. This vulnerability arises from a missing capability check in the 'wcta2w_get_amazon_product_callback()' function. Attackers can exploit this flaw to create new products without authentication, compromising the integrity of the WordPress site. Users are advised to update to the latest version to mitigate this risk.
Affected Version(s)
Amazon Products to WooCommerce * <= 1.2.7