VYPR
Medium severity6.5NVD Advisory· Published Dec 30, 2025· Updated Apr 27, 2026

CVE-2025-69024

CVE-2025-69024

Description

Missing Authorization vulnerability in bizswoop BizPrint print-google-cloud-print-gcp-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BizPrint: from n/a through <= 4.6.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

BizPrint WordPress plugin <=4.6.7 has a missing authorization vulnerability allowing unauthenticated attackers to exploit broken access controls.

Vulnerability

Overview

The BizPrint plugin for WordPress (print-google-cloud-print-gcp-woocommerce) contains a missing authorization vulnerability in versions up to and including 4.6.7. This is a broken access control issue where the plugin fails to properly verify user permissions or nonce tokens in certain functions, leading to incorrectly configured access control security levels [1].

Exploitation

Attackers can exploit this vulnerability without requiring authentication, as the missing authorization check allows unprivileged users to perform actions that should be restricted to higher-privileged roles. The vulnerability is particularly concerning because it can be used in mass-exploit campaigns targeting thousands of websites regardless of their size or popularity [1].

Impact

Successful exploitation enables an attacker to bypass access controls and potentially execute unauthorized actions within the plugin's functionality that should be protected. While the CVSS score of 6.5 indicates a medium severity, the broken access control can lead to unauthorized data access or modification, depending on the affected functions [1].

Mitigation

The vulnerability has been patched in version 4.7.1 of the BizPrint plugin. Users are strongly advised to update immediately. For those unable to update, contacting a hosting provider or web developer for assistance is recommended. Patchstack users can enable auto-updates for vulnerable plugins [1]

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.