CVE-2025-31000

Missing Authorization vulnerability in Miguel Fuentes Payment QR WooCommerce payment-qr-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment QR WooCommerce: from n/a through <= 1.1.6.
Configurations

No configuration.

History

23 Apr 2026, 15:27

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

01 Apr 2026, 17:20

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : unknown
Summary
  • (es) La vulnerabilidad de falta de autorización en Miguel Fuentes Payment QR WooCommerce permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta al código QR de pago de WooCommerce desde la versión n/d hasta la 1.1.6.
Summary (en) Missing Authorization vulnerability in Miguel Fuentes Payment QR WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Payment QR WooCommerce: from n/a through 1.1.6. (en) Missing Authorization vulnerability in Miguel Fuentes Payment QR WooCommerce payment-qr-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment QR WooCommerce: from n/a through <= 1.1.6.
References
  • {'url': 'https://patchstack.com/database/wordpress/plugin/payment-qr-woo/vulnerability/wordpress-payment-qr-woocommerce-1-1-6-broken-access-control-vulnerability?_s_id=cve', 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/payment-qr-woo/vulnerability/wordpress-payment-qr-woocommerce-1-1-6-broken-access-control-vulnerability?_s_id=cve -

06 Jun 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-06 13:15

Updated : 2026-04-23 15:27


NVD link : CVE-2025-31000

Mitre link : CVE-2025-31000

CVE.ORG link : CVE-2025-31000


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization