CVE-2025-14357
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows attackers with at least Subscriber-level access to create new pages and change site settings on a WordPress site using the Mega Store Woocommerce theme. The issue arises because the system doesn't properly check if the user has permission to make these changes, making it easier for unauthorized users to manipulate the site.
Technical Description
The Mega Store Woocommerce theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the setup_widgets() function in core/includes/importer/whizzie.php in all versions up to, and including, 5.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary pages and modify site settings.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Feb 19, 2026
about 2 months ago
Last Modified
Feb 19, 2026
about 2 months ago