Description
The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcta2w_get_amazon_product_callback() function in all versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to create new produces.
Published: 2025-06-26
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Product Creation
Action: Immediate Patch
AI Analysis

Impact

The Amazon Products to WooCommerce plugin contains a missing capability check in the wcta2w_get_amazon_product_callback() function. This omission permits unauthenticated attackers to invoke the callback and create new WooCommerce products without proper authorization. The vulnerability could be abused to inject unwanted products into a store, potentially leading to defacement, misinformation, or redirecting traffic to malicious content. The attack consumes only the ability to send an HTTP request to the plugin’s callback endpoint, with no need for elevated privileges or complex setup.

Affected Systems

WordPress sites running the Amazon Products to WooCommerce plugin version 1.2.7 or earlier are affected. The plugin is developed by the vendor suhailahmad64 and is distributed through the WordPress plugin repository. Any installation of the plugin prior to version 1.2.8 is vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% suggests low exploitation probability at the current time. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the flaw by sending a crafted request to the exposed callback endpoint; no additional authentication is required, so the vector is likely web-based and publicly reachable. Although the risk remains moderate, the lack of authorization makes the flaw significant enough to warrant prompt remediation.

Generated by OpenCVE AI on April 21, 2026 at 20:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Amazon Products to WooCommerce plugin to the latest version that includes a proper capability check.
  • If an update is not available or the plugin is not needed, remove it entirely from the WordPress installation to eliminate the attack surface.
  • Configure WordPress role and capability settings to ensure that only authorized administrators or shop managers can create WooCommerce products; verify that no other user role has the capability to access the callback endpoint.

Generated by OpenCVE AI on April 21, 2026 at 20:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28662 The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcta2w_get_amazon_product_callback() function in all versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to create new produces.
History

Mon, 07 Jul 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Suhailahmad64
Suhailahmad64 amazon Products To Woocommerce
CPEs cpe:2.3:a:suhailahmad64:amazon_products_to_woocommerce:*:*:*:*:*:wordpress:*:*
Vendors & Products Suhailahmad64
Suhailahmad64 amazon Products To Woocommerce

Thu, 26 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Jun 2025 03:00:00 +0000

Type Values Removed Values Added
Description The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcta2w_get_amazon_product_callback() function in all versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to create new produces.
Title Amazon Products to WooCommerce <= 1.2.7 - Missing Authorization to Unauthenticated Arbitrary Product Creation
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Suhailahmad64 Amazon Products To Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:12:14.099Z

Reserved: 2025-06-06T16:06:46.182Z

Link: CVE-2025-5813

cve-icon Vulnrichment

Updated: 2025-06-26T13:22:33.285Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-26T03:15:24.800

Modified: 2025-07-07T16:04:42.837

Link: CVE-2025-5813

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T20:15:44Z

Weaknesses