Skip to content
COOEY

EXPOSURES › CVE-2025-10656

CVE-2025-10656

CRITICAL
DETAIL
SourceNVD · cve Published2026-07-29 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-10656 ↗

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes it possible for unauthenticated attackers to create admin accounts.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.