Access Control Vulnerability in Bux Woocommerce by Bux
CVE-2025-60247

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 November 2025

What is CVE-2025-60247?

The Bux Woocommerce plugin for WordPress is susceptible to a missing authorization vulnerability that may allow unauthorized access to certain functionalities due to inadequate access control lists (ACLs). This issue is present in all versions up to 1.2.3, prompting immediate attention from website administrators to safeguard their systems from potential exploitation.

Affected Version(s)

Bux Woocommerce <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ch4r0n | Patchstack Bug Bounty Program
.
CVE-2025-60247 : Access Control Vulnerability in Bux Woocommerce by Bux