VYPR
Medium severity5.3NVD Advisory· Published Dec 30, 2025· Updated Apr 27, 2026

CVE-2025-68993

CVE-2025-68993

Description

Missing Authorization vulnerability in XforWooCommerce Share, Print and PDF Products for WooCommerce share-print-pdf-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share, Print and PDF Products for WooCommerce: from n/a through <= 3.1.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Share, Print and PDF Products for WooCommerce (≤3.1.2) allows unauthenticated attackers can exploit incorrectly configured access controls.

The Share, Print and PDF Products for WooCommerce plugin (versions up to and including 3.1.2) contains a missing authorization vulnerability. The root cause is a broken access control issue where the plugin fails to properly verify user permissions or enforce access rights for certain functions, allowing unprivileged users to perform actions intended for higher-privileged roles [1].

Exploitation requires an authenticated user account, but no special privileges are needed. The vulnerability is triggered by sending crafted requests to the plugin's endpoints that lack proper nonce or capability checks. This type of flaw is commonly targeted in mass-exploit campaigns against WordPress sites [1].

An attacker who successfully exploits this vulnerability can execute higher-privileged actions, such as modifying plugin settings or accessing restricted features, without authorization. The impact is limited to the affected by the specific functions exposed, but the lack of access control can lead to unauthorized data exposure or configuration changes [1].

As an immediate mitigation, users should update the plugin to a patched version of the plugin if available. If an update is not possible, site administrators should consult their hosting provider or web developer to apply workarounds, such as restricting access to the plugin's endpoints via server-level rules [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.