CVE-2025-67599
Description
Missing Authorization vulnerability in WebToffee WebToffee eCommerce Marketing Automation decorator-woocommerce-email-customizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebToffee eCommerce Marketing Automation: from n/a through <= 2.1.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The WebToffee eCommerce Marketing Automation plugin for WordPress ≤2.1.1 has a missing authorization vulnerability allowing unauthenticated access to privileged functions.
The WebToffee eCommerce Marketing Automation plugin (decorator-woocommerce-email-customizer) for WordPress contains a broken access control vulnerability in versions up to and including 2.1.1. The issue stems from missing authorization checks in one or more functions, meaning access control security levels are not properly enforced. This allows an unprivileged user to execute actions that should require higher privileges [1].
Exploitation does not require authentication; an attacker can send crafted requests to the vulnerable endpoint without any prior login. The attack surface is the plugin's REST API or admin-facing functions that lack proper capability checks. No specific network position is needed beyond standard internet access to the target site [1].
An attacker exploiting this vulnerability can perform unauthorized administrative actions, such as modifying plugin settings, accessing sensitive data, or altering email templates. While the CVSS v3 score of 4.3 indicates medium severity, the vulnerability is considered low severity in the WordPress context and unlikely to be exploited in mass campaigns, though similar flaws are often used in automated attacks [1].
A patched version 2.1.2 is available, and users are advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. For those unable to update, contacting a hosting provider or web developer for assistance is recommended [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=2.1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.