Security Advisory: This update addresses a Missing Authorization vulnerability (CVE-2025-14270) that allowed authenticated users with Editor role or higher to modify plugin settings without proper authorization.
Credits: Thank you to the Wordfence security team for responsible disclosure.
Security Advisory: This update addresses a potential IDOR (Insecure Direct Object Reference) vulnerability that could allow unauthorized access to order details.
Credits: Thank you very much to Md Shofiur R. from Pentest Testing Corp for responsible disclosure.
Plugin Website
Visit website
Share Post
Get insights into what’s happening at ChangelogWP right in your inbox. We don’t believe in spam.