The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcta2w_get_amazon_product_callback() function in all versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to create new produces.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 07 Jul 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Suhailahmad64
Suhailahmad64 amazon Products To Woocommerce
CPEs cpe:2.3:a:suhailahmad64:amazon_products_to_woocommerce:*:*:*:*:*:wordpress:*:*
Vendors & Products Suhailahmad64
Suhailahmad64 amazon Products To Woocommerce

Thu, 26 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Jun 2025 03:00:00 +0000

Type Values Removed Values Added
Description The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcta2w_get_amazon_product_callback() function in all versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to create new produces.
Title Amazon Products to WooCommerce <= 1.2.7 - Missing Authorization to Unauthenticated Arbitrary Product Creation
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-06-26T13:22:38.596Z

Reserved: 2025-06-06T16:06:46.182Z

Link: CVE-2025-5813

cve-icon Vulnrichment

Updated: 2025-06-26T13:22:33.285Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-26T03:15:24.800

Modified: 2025-07-07T16:04:42.837

Link: CVE-2025-5813

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.