CVE-2025-30825
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-30825 is a newly disclosed vulnerability affecting WPClever WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce. This missing authorization issue permits privilege escalation, allowing unauthorized users to gain higher access levels within the affected plugin. The vulnerability spans from version n/a to 1.3.5, putting a significant number of WooCommerce sites at risk. Unauthenticated attackers can exploit this flaw to modify or access sensitive data, potentially leading to serious security consequences. It is recommended that users upgrade to the latest version of the plugin, WPClever WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce, to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.