CVE-2025-49287

Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Feed for WooCommerce: from n/a through <= 2.2.8.
CVSS

No CVSS.

Configurations

No configuration.

History

01 Apr 2026, 17:24

Type Values Removed Values Added
References
  • {'url': 'https://patchstack.com/database/wordpress/plugin/webtoffee-product-feed/vulnerability/wordpress-product-feed-for-woocommerce-2-2-8-broken-access-control-vulnerability?_s_id=cve', 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/webtoffee-product-feed/vulnerability/wordpress-product-feed-for-woocommerce-2-2-8-broken-access-control-vulnerability?_s_id=cve -
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : unknown
Summary
  • (es) La vulnerabilidad de falta de autorización en WebToffee Product Feed for WooCommerce permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta al feed de productos para WooCommerce desde n/d hasta la versión 2.2.8.
Summary (en) Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Feed for WooCommerce: from n/a through 2.2.8. (en) Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Feed for WooCommerce: from n/a through <= 2.2.8.

06 Jun 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-06 13:15

Updated : 2026-04-01 17:24


NVD link : CVE-2025-49287

Mitre link : CVE-2025-49287

CVE.ORG link : CVE-2025-49287


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization