Missing Authorization Vulnerability in ilmosys Open Close WooCommerce Store Plugin
CVE-2025-62935
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 October 2025
What is CVE-2025-62935?
The ilmosys Open Close WooCommerce Store plugin has a missing authorization vulnerability that allows attackers to exploit incorrectly configured access control security levels. This issue could enable unauthorized access to sensitive functionalities and could compromise the overall security of the WooCommerce environment. Users are advised to review their plugin configurations and update to secure versions to mitigate potential risks.
Affected Version(s)
Open Close WooCommerce Store <= n/a