Build Private Store For Woocommerce <= 1.0 - Missing Authorization
medium
The Build Private Store For Woocommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.0
- Fixed in:
- 1.1
- Disclosed:
- Jan 24, 2025
CVE-2025-24633 on NVD →
Build Private Store For Woocommerce <= 1.0 - Cross-Site Request Forgery
medium
The Build Private Store For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged req...
- CVSS:
- 4.3
- Affected:
- up to 1.0
- Fixed in:
- 1.1
- Disclosed:
- Jan 14, 2025
CVE-2025-22731 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database