EXPOSURES › CVE-2025-10656
CVE-2025-10656
CRITICAL
DETAIL
SourceNVD · cve
Published2026-07-29
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-10656 ↗
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
DESCRIPTION
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes it possible for unauthenticated attackers to create admin accounts.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.