CVE-2025-49888
7.1Pimwick · PW WooCommerce On Sale!
A missing authorization vulnerability in the PW WooCommerce On Sale! plugin allows authenticated users with low privileges to perform unauthorized actions due to incorrect access control.
Executive summary
A missing authorization flaw in the Pimwick PW WooCommerce On Sale! plugin allows authenticated attackers to potentially impact site integrity and availability.
Vulnerability
The vulnerability is a missing authorization flaw (CWE-862) affecting the plugin's access control mechanisms. It allows a low-privileged authenticated user to perform unauthorized actions, potentially leading to a denial of service or unauthorized data modification.
Business impact
This vulnerability poses a significant risk to e-commerce operations by allowing unauthorized users to manipulate sale configurations or disrupt store functionality. With a CVSS score of 7.1, the high severity reflects the potential for operational downtime and the compromise of store integrity, which could result in direct financial loss and reputational damage.
Remediation
Immediate Action: Administrators should immediately audit the installation of the PW WooCommerce On Sale! plugin and restrict access to administrative functions until a vendor-supplied patch is applied.
Proactive Monitoring: Review WordPress access logs for unusual activity originating from low-privileged user accounts, specifically monitoring for unexpected configuration changes or performance degradation.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized requests to the plugin's sensitive endpoints, providing a layer of protection until the vendor releases a definitive fix.
Exploitation status
Public Exploit Available: No — exploit_available (false).
Analyst recommendation
Given the potential for service disruption and unauthorized configuration changes, organizations utilizing this plugin must prioritize its security. Administrators should monitor the vendor's official channels for the release of a patched version and ensure that the plugin is updated to the latest release as soon as it becomes available to remediate the underlying access control weakness.
Sources
Originally found and disclosed by theviper17 | Patchstack Bug Bounty Program, per the CVE Program record.