VYPR
High severity7.1NVD Advisory· Published May 26, 2026

CVE-2025-14361

CVE-2025-14361

Description

Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Woocommerce Envato Affiliates: from n/a through 1.2.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in WooCommerce Envato Affiliates plugin (≤1.2.1) allows unauthenticated attackers to change plugin settings.

Vulnerability

The WooCommerce Envato Affiliates plugin by AA-Team versions up to and including 1.2.1 suffers from a missing authorization vulnerability. The plugin fails to properly check permissions on certain functionality, allowing access to settings that should be restricted to administrators. This affects all installations using the plugin without the latest patch.

Exploitation

An unauthenticated attacker can exploit this vulnerability by sending crafted requests to the vulnerable endpoints. No authentication or user interaction is required. The attack can be performed remotely over the network. The Patchstack advisory [1] indicates this vulnerability is expected to be used in mass-exploit campaigns targeting thousands of websites.

Impact

Successful exploitation allows an attacker to change plugin settings without authorization. This could lead to unauthorized modifications of the affiliate configuration, potentially redirecting commissions or altering integration with Envato. The CVSS score of 7.1 (High) reflects the moderate impact but ease of exploitation.

Mitigation

The vendor has not released a patched version as of the publication date. The recommended immediate action is to update the plugin if a fix becomes available. If unable to update, users should contact their hosting provider or web developer for assistance. The vulnerability is listed as expected to be exploited, so prompt action is advised [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.