


Perceptive Security
SOC/SIEM Consultancy

The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i…
Published:
28 juli 2026 om 22:00:00
Alert date:
29 juli 2026 om 11:00:56
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2025-10656 affects the Spreadsheet Price Changer for WooCommerce and WP E-commerce Light plugin for WordPress in all versions up to and including 2.4.37. The vulnerability exists in the user_filter function due to missing authorization checks. Unauthenticated attackers can exploit this flaw to create administrator accounts on affected WordPress sites. This represents a critical privilege escalation risk as it grants full administrative control to unauthorized parties. No authentication is required to exploit the vulnerability, making it accessible to any remote attacker. Site owners using the affected plugin versions should update immediately or apply mitigations. The vulnerability was reported via NVD and corroborated by Wordfence threat intelligence.
Technical details
Mitigation steps:
Affected products:
Spreadsheet Price Changer for WooCommerce and WP E-commerce Light plugin
WordPress
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-10656
https://plugins.trac.wordpress.org/browser/excel-like-price-change-for-woocommerce-and-wp-e-commerce-light/trunk/sellingcommander.php#L3725
https://www.wordfence.com/threat-intel/vulnerabilities/id/1f891b68-72c4-4f94-bd49-52576ad710f9?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
