CVE-2025-31377
No known patch is available for this vulnerability.
The affected plugin has been removed from the WordPress.org directory (reason: Security Issue), and no patched version is being distributed through the official directory. If you have the affected software installed, you should uninstall or replace it rather than wait for an update.
Description
Missing authorization in Woo Product Feed For Marketing Channels up to v1.9.0 allows unauthenticated attackers to exploit access control flaws.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in Woo Product Feed For Marketing Channels up to v1.9.0 allows unauthenticated attackers to exploit access control flaws.
Vulnerability
The Woo Product Feed For Marketing Channels plugin for WordPress (slug: woocommerce-to-google-merchant-center) contains a Missing Authorization vulnerability affecting versions from n/a through 1.9.0. The flaw resides in the plugin's access control logic, which fails to properly validate user permissions for certain actions, allowing exploitation of incorrectly configured access control security levels. The plugin has been closed and removed from the WordPress.org plugin directory as of April 9, 2025 due to this security issue [1].
Exploitation
An attacker can exploit this vulnerability without requiring authentication or any special privileges. By sending crafted HTTP requests to the vulnerable endpoints, an attacker can bypass the intended authorization checks. No direct user interaction is needed, and the attack can be launched remotely over the network.
Impact
Successful exploitation allows an attacker to perform unauthorized actions within the plugin's context, potentially leading to the disclosure or modification of sensitive data, such as product feed configurations or marketing channel settings. The full scope of impact is not detailed in the available references, but the high severity CVSS score (7.5) and the plugin's removal from the official directory indicate a significant risk.
Mitigation
No patched version is available, as the plugin was closed and removed from the WordPress.org plugin repository on April 9, 2025 without any prior security update [1]. Users who have this plugin installed should uninstall it immediately. There is no official workaround provided in the available references. This CVE is not listed on CISA's Known Exploited Vulnerabilities catalog.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.9.0
- Range: <=1.9.0
Patches
0woocommerce-to-google-merchant-centerThis plugin has been removed from the WordPress.org directory on 2025-04-09 (reason: Security Issue). No patched version is being distributed through the official directory. Users who have it installed should uninstall it.
Source: api.wordpress.org · directory page
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.