CVE-2025-47463 HIGH

CVE-2025-47463: WordPress Stock Locations for WooCommerce plugin <= 2.8.6 - Broken Access Control Vulnerability

Vendor Fahad Mahmood
Product Stock Locations for WooCommerce
Weakness CWE-862 · Missing authorization
Published June 9, 2025
Last update April 28, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

What the vulnerability does

01Description

Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce stock-locations-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Locations for WooCommerce: from n/a through <= 2.8.6.

Explanation of Vulnerability in Simple Terms

02Summary

Stock Locations for WooCommerce versions up to 2.8.6 lack proper authorization checks, allowing authenticated users with low privileges to modify site data and disrupt service availability. An attacker with a basic user account can alter inventory locations and cause the site to become unavailable. Update to a version newer than 2.8.6.

What an attacker can do

03Attacker Capabilities

Modify inventory data and make the site unavailable.

Potential impact on your site

04Site Impact

Inventory data can be corrupted and the site may become inaccessible to customers.

Conditions required to exploit

05Prerequisites

Attacker needs a low-privilege user account (e.g., customer or subscriber role).

Key dates

06Disclosure timeline

June 9, 2025 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE