Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in mediaticus Subaccounts for WooCommerce subaccounts-for-woocommerce allows Authentication Abuse.This issue affects Subaccounts for WooCommerce: from n/a through <= 1.6.6.
Published: 2025-05-23
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Subaccounts for WooCommerce plugin enables an attacker to bypass normal authentication checks by using an alternate path or channel, effectively allowing unauthorized access to a user account. The vulnerability permits an authenticated or unauthenticated attacker to gain the rights associated with the compromised account, potentially exposing sensitive data or compromising the entire site. The weakness is classified as CWE‑288, an authentication abuse vulnerability.

Affected Systems

The affected product is the MediaTicucous Subaccounts for WooCommerce WordPress plugin on all installations from any release through 1.6.6 inclusive. WordPress sites that have installed this plugin version are at risk. No specific version prior to 1.6.6 is separate; the entire range up to and including 1.6.6 is vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity with a significant impact on confidentiality, integrity, and availability through compromised accounts. The EPSS score of less than 1% suggests that exploitation, while possible, is unlikely at present but persists as a known risk. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be via privileged user or administrative interfaces that allow the alternate authentication path to be exploited; specific prerequisites are not detailed in the description.

Generated by OpenCVE AI on April 30, 2026 at 19:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Subaccounts for WooCommerce plugin to the latest available version (e.g., 1.6.7 or later).
  • If an update is not immediately available, consider disabling or removing the plugin from the WordPress installation until a patch is released.
  • Restrict administrative access by limiting the number of users with high‑privilege roles and monitor account activity for suspicious changes.

Generated by OpenCVE AI on April 30, 2026 at 19:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28085 Authentication Bypass Using an Alternate Path or Channel vulnerability in mediaticus Subaccounts for WooCommerce allows Authentication Abuse. This issue affects Subaccounts for WooCommerce: from n/a through 1.6.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Authentication Bypass Using an Alternate Path or Channel vulnerability in mediaticus Subaccounts for WooCommerce allows Authentication Abuse. This issue affects Subaccounts for WooCommerce: from n/a through 1.6.6. Authentication Bypass Using an Alternate Path or Channel vulnerability in mediaticus Subaccounts for WooCommerce subaccounts-for-woocommerce allows Authentication Abuse.This issue affects Subaccounts for WooCommerce: from n/a through <= 1.6.6.
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Fri, 23 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 23 May 2025 13:00:00 +0000

Type Values Removed Values Added
Description Authentication Bypass Using an Alternate Path or Channel vulnerability in mediaticus Subaccounts for WooCommerce allows Authentication Abuse. This issue affects Subaccounts for WooCommerce: from n/a through 1.6.6.
Title WordPress Subaccounts for WooCommerce plugin <= 1.6.6 - Account Takeover vulnerability
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Mediaticus Subaccounts For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:20:15.564Z

Reserved: 2025-05-07T09:38:48.852Z

Link: CVE-2025-47461

cve-icon Vulnrichment

Updated: 2025-05-23T14:58:14.470Z

cve-icon NVD

Status : Deferred

Published: 2025-05-23T13:15:38.007

Modified: 2026-04-23T15:30:15.700

Link: CVE-2025-47461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T19:15:16Z

Weaknesses