VYPR

Perfit Woocommerce

by WordPress

Source repositories

CVEs (1)

  • CVE-2025-14173MedJan 14, 2026
    risk 0.34cvss 5.3epss 0.00

    The Perfit WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.1. This is due to missing authorization checks on the `logout` function called via the `actions` function hooked to `admin_init`. This makes it possible for unauthenticated attackers to delete arbitrary plugin settings via the `action` parameter.