CVE-2025-52800

7.3

Unity Business Technology Pty Ltd · The E-Commerce ERP

The E-Commerce ERP plugin for WordPress contains a missing authorization vulnerability that allows unauthenticated attackers to access restricted functionality.

Executive summary

A missing authorization flaw in The E-Commerce ERP plugin exposes sensitive functionality to unauthenticated remote attackers, necessitating urgent attention.

Vulnerability

This vulnerability is a classic CWE-862 Missing Authorization flaw, where the software fails to verify the identity or permissions of a user before granting access to protected functions. Because the CVSS vector indicates no authentication is required (PR:N) and no user interaction is necessary (UI:N), an unauthenticated attacker can execute restricted operations via the network.

Business impact

The ability for an unauthenticated user to interact with restricted ERP functions presents a significant risk to data integrity and confidentiality. With a CVSS score of 7.3, this high-severity vulnerability could allow unauthorized actors to manipulate business processes or access sensitive records, potentially leading to financial loss or regulatory non-compliance.

Remediation

Immediate Action: Administrators should check the vendor advisory or the Patchstack database for the release of a security update and apply it immediately to versions 2.1.1.3 and below. If a patch is currently unavailable, consider disabling or removing the plugin until a secure version is released.

Proactive Monitoring: Review web server access logs for unusual patterns or requests directed at the E-Commerce ERP plugin endpoints that originate from unauthorized or unexpected IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious or unauthorized requests to known plugin endpoints, providing a layer of protection until the software is patched.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS score and the nature of the missing authorization, this vulnerability poses a clear risk to any organization relying on The E-Commerce ERP. Organizations must prioritize identifying instances of this plugin and apply vendor updates as soon as they become available to prevent unauthorized system access.

More Unity Business Technology Pty Ltd CVEs

Sources

Originally found and disclosed by ch4r0n | Patchstack Bug Bounty Program, per the CVE Program record.