Hide Category by User Role for WooCommerce <= 2.3.1 - Missing Authorization to Unauthenticated Cache Flushing
medium
The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.1. This is due to a missing capability check on the admin_init hook that executes wp_cache_flush(). This makes it possible for unauthenticated attackers to flush the site'...
- CVSS:
- 5.3
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Nov 26, 2025
CVE-2025-13441 on NVD →
Hide Category by User Role for WooCommerce <= 2.1.1 - Missing Authorization
medium
The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized act...
- CVSS:
- 4.3
- Affected:
- up to 2.1.1
- Fixed in:
- 2.2
- Disclosed:
- Jan 3, 2025
CVE-2024-56272 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database