GHSA-p226-wwrr-fmwwCriticalCVSS 9.8
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is...
🔗 CVE IDs covered (1)
📋 Description
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes it possible for unauthenticated attackers to create admin accounts.
🔗 References (4)
- https://nvd.nist.gov/vuln/detail/CVE-2025-10656
- https://plugins.trac.wordpress.org/browser/excel-like-price-change-for-woocommerce-and-wp-e-commerce-light/trunk/sellingcommander.php#L3725
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1f891b68-72c4-4f94-bd49-52576ad710f9?source=cve
- https://github.com/advisories/GHSA-p226-wwrr-fmww