Description
Missing Authorization vulnerability in Constant Contact Constant Contact + WooCommerce constant-contact-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Constant Contact + WooCommerce: from n/a through <= 2.4.1.
Published: 2025-12-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw inside the Constant Contact + WooCommerce plugin for WordPress. An attacker can send requests to plugin endpoints that are not properly protected, enabling them to perform actions that should be restricted to privileged users. The flaw allows unauthorized reading or modification of plugin data, potentially exposing customer information or altering e‑commerce behavior. This is a typical Access Control Robustness weakness identified as CWE‑862.

Affected Systems

The flaw affects the Constant Contact + WooCommerce plugin for WordPress. All versions from the earliest release up through 2.4.1 are vulnerable. In particular, any installation running an affected version is susceptible. The plugin is installed within a WordPress site, and the vulnerability is present regardless of whether the site uses WooCommerce or not, as long as the plugin is active.

Risk and Exploitability

The vendor has assigned a CVSS score of 5.3, indicating moderate severity, and the EPSS score is below 1 %, implying a low likelihood of exploitation currently. The likely attack vector is web‑based, requiring an unauthenticated or minimally privileged web request to the plugin’s endpoint. Because the flaw allows unauthorized actions that could expose or manipulate sensitive data, the risk remains valid even though it is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on April 29, 2026 at 19:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Constant Contact + WooCommerce plugin to version 2.5 or later, which contains the access‑control fix.
  • If an immediate update is not possible, restrict access to the plugin’s endpoints by adding role checks or placing the plugin directory behind authentication middleware.
  • Verify that only users with the administrator capability can perform privileged plugin actions and review any custom role assignments to enforce correct access control.

Generated by OpenCVE AI on April 29, 2026 at 19:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 11 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress

Tue, 09 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Constant Contact Constant Contact + WooCommerce constant-contact-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Constant Contact + WooCommerce: from n/a through <= 2.4.1.
Title WordPress Constant Contact + WooCommerce plugin <= 2.4.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Woocommerce Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:21.957Z

Reserved: 2025-12-09T12:21:34.120Z

Link: CVE-2025-67580

cve-icon Vulnrichment

Updated: 2025-12-09T14:51:10.158Z

cve-icon NVD

Status : Deferred

Published: 2025-12-09T16:18:35.640

Modified: 2026-04-27T18:16:44.327

Link: CVE-2025-67580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T19:45:18Z

Weaknesses