Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37 - Missing Authorization to Unauthenticated Privilege Escalation via Admin Account Creation
critical
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes it possible for unauthenticated attackers to create admin accounts.
- CVSS:
- 9.8
- Affected:
- up to 2.4.37
- Fix:
- No patched version reported
- Disclosed:
- Jul 28, 2026
CVE-2025-10656 on NVD →
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light [excel-like-price-change-for-woocommerce-and-wp-e-commerce-light] <= 2.4.37 (unfixed)
unknown
[en] Incorrect Privilege Assignment vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light allows Privilege Escalation. This issue affects Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light: from n/a through 2.4.37.
- Affected:
- up to 2.4.37
- Fix:
- No patched version reported
- Disclosed:
- Jun 9, 2025
CVE-2025-48129 on NVD →
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light [excel-like-price-change-for-woocommerce-and-wp-e-commerce-light] <= 2.4.37 (unfixed)
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light allows Code Injection. This issue affects Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light: from n/a through 2.4.37.
- Affected:
- up to 2.4.37
- Fix:
- No patched version reported
- Disclosed:
- Jun 9, 2025
CVE-2025-48123 on NVD →
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light [excel-like-price-change-for-woocommerce-and-wp-e-commerce-light] <= 2.4.37 (unfixed)
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light allows Path Traversal. This issue affects Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light: from n/a through 2.4....
- Affected:
- up to 2.4.37
- Fix:
- No patched version reported
- Disclosed:
- Jun 9, 2025
CVE-2025-48124 on NVD →
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light [excel-like-price-change-for-woocommerce-and-wp-e-commerce-light] <= 2.4.37 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light allows SQL Injection. This issue affects Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light: from n/a through...
- Affected:
- up to 2.4.37
- Fix:
- No patched version reported
- Disclosed:
- Jun 9, 2025
CVE-2025-48122 on NVD →
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37 - Unauthenticated SQL Injection
high
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.37 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unaut...
- CVSS:
- 7.5
- Affected:
- up to 2.4.37
- Fix:
- No patched version reported
- Disclosed:
- Jun 3, 2025
CVE-2025-48122 on NVD →
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37 - Unauthenticated Arbitrary File Download
high
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.37. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive informat...
- CVSS:
- 7.5
- Affected:
- up to 2.4.37
- Fix:
- No patched version reported
- Disclosed:
- May 30, 2025
CVE-2025-48124 on NVD →
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37 - Unauthenticated Remote Code Execution
critical
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.37. This makes it possible for unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 2.4.37
- Fix:
- No patched version reported
- Disclosed:
- May 21, 2025
CVE-2025-48123 on NVD →
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37 - Unauthenticated Privilege Escalation
critical
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.37. This makes it possible for unauthenticated attackers to register as an administrator.
- CVSS:
- 9.8
- Affected:
- up to 2.4.37
- Fix:
- No patched version reported
- Disclosed:
- May 20, 2025
CVE-2025-48129 on NVD →
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light [excel-like-price-change-for-woocommerce-and-wp-e-commerce-light] <= 2.4.37 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light allows PHP Local File Inclusion. This issue affects Spreadsheet Price Changer for WooCommerce and WP E-comm...
- Affected:
- up to 2.4.37
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2025
CVE-2025-39378 on NVD →
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37 - Unauthenticated Local File Inclusion
critical
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.37. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code i...
- CVSS:
- 9.8
- Affected:
- up to 2.4.37
- Fix:
- No patched version reported
- Disclosed:
- Apr 21, 2025
CVE-2025-39378 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database