Privilege Escalation Vulnerability in Appy Pie Connect for WooCommerce Plugin
CVE-2025-9286
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2025
What is CVE-2025-9286?
The Appy Pie Connect for WooCommerce plugin for WordPress suffers from a privilege escalation vulnerability found in the reset_user_password() REST handler. This vulnerability, present in all versions up to and including 1.1.2, allows unauthenticated attackers to exploit the absence of proper authorization checks. By leveraging this flaw, attackers can reset the passwords of arbitrary user accounts, including those of administrators, thereby potentially gaining unauthorized administrative access to the system.
Affected Version(s)
Appy Pie Connect for WooCommerce * <= 1.1.2