Privilege Escalation Vulnerability in Appy Pie Connect for WooCommerce Plugin
CVE-2025-9286

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 October 2025

What is CVE-2025-9286?

The Appy Pie Connect for WooCommerce plugin for WordPress suffers from a privilege escalation vulnerability found in the reset_user_password() REST handler. This vulnerability, present in all versions up to and including 1.1.2, allows unauthenticated attackers to exploit the absence of proper authorization checks. By leveraging this flaw, attackers can reset the passwords of arbitrary user accounts, including those of administrators, thereby potentially gaining unauthorized administrative access to the system.

Affected Version(s)

Appy Pie Connect for WooCommerce * <= 1.1.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JohSka
.
CVE-2025-9286 : Privilege Escalation Vulnerability in Appy Pie Connect for WooCommerce Plugin