VYPR
Critical severity9.8NVD Advisory· Published Jul 29, 2026· Updated Jul 30, 2026No known patch

CVE-2025-10656

CVE-2025-10656

Description

The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes it possible for unauthenticated attackers to create admin accounts.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

2