Authorization Flaw in Themeisle PPOM for WooCommerce
CVE-2025-66069
4.3MEDIUM
What is CVE-2025-66069?
A missing authorization vulnerability exists in the Themeisle PPOM for WooCommerce plugin, specifically within the woocommerce-product-addon configuration. This flaw allows attackers to exploit incorrectly configured access control security levels. The vulnerability affects all versions from an unspecified release up to and including 33.0.16, potentially enabling unauthorized users to gain access to sensitive functionalities of the plugin.
Affected Version(s)
PPOM for WooCommerce <= n/a