VYPR
Medium severity5.4NVD Advisory· Published May 7, 2025· Updated Apr 23, 2026

CVE-2025-47602

CVE-2025-47602

Description

Missing Authorization vulnerability in ammarahmad786 Calculate Prices based on Distance For WooCommerce calculate-prices-based-on-distance-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Calculate Prices based on Distance For WooCommerce: from n/a through <= 1.3.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization vulnerability in WordPress Calculate Prices based on Distance plugin allows unprivileged users to access higher privileged functions, patched in version 1.3.6.

The vulnerability is a missing authorization check in the WordPress plugin 'Calculate Prices based on Distance For WooCommerce' (versions <=1.3.5). This allows exploitation of incorrectly configured access control security levels, meaning functions that should require higher privileges are accessible to lower-privileged users or even unauthenticated visitors [1].

An attacker can exploit this by sending crafted requests to vulnerable endpoints without proper capability checks. No authentication is required, making it possible for anyone with access to the site to trigger the vulnerability. The attack surface is any WordPress site running the affected plugin version [1].

Successful exploitation enables an attacker to perform actions that should be restricted, such as modifying plugin settings or accessing sensitive data. This could lead to unauthorized changes in price calculations or other administrative functions, potentially affecting e-commerce operations [1].

The vendor has patched the issue in version 1.3.6. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. The vulnerability is considered low severity but is still a risk for sites using affected versions [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.