Privilege Escalation Risk in WooCommerce Multi Locations Inventory Management Plugin by WordPress
CVE-2025-9054

9.8CRITICAL

What is CVE-2025-9054?

The WooCommerce Multi Locations Inventory Management plugin for WordPress is susceptible to unauthorized data modification due to a lack of capability checks in the 'wcmlim_settings_ajax_handler' function. This vulnerability allows unauthenticated attackers to modify various options on the WordPress site, including changing the default user role during registrations to administrator and potentially enabling user registrations for attackers. Exploiting this flaw can lead to unauthorized administrative access, posing significant security risks to affected sites.

Affected Version(s)

MultiLoca - WooCommerce Multi Locations Inventory Management * <= 4.2.8

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thái An
.