SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2025-10656

CRITICAL · CVSS 9.8 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable due to a missing authorization flaw in the user_filter function, allowing unauthenticated attackers to create admin accounts. This critical vulnerability (CVSS 9.8) poses a significant risk to any WordPress site using this plugin, as it can lead to unauthorized access and potential site compromise. WordPress administrators using this plugin should prioritize immediate updates to mitigate the risk.

CVE
CVE-2025-10656
Severity
CRITICAL
CVSS
9.8
EPSS
0.36%
WordPress

Original NVD Description

The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes it possible for unauthenticated attackers to create admin accounts.