CVE-2025-66089 - CERT CVE
ID CVE-2025-66089
Sažetak Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Feed for WooCommerce: from n/a through <= 2.3.1.
Reference
CVSS
Base: 4.3
Impact: 3.4
Exploitability:0.9
Pristup
VektorSloženostAutentikacija
NETWORK LOW HIGH
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW LOW
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
Zadnje važnije ažuriranje 20-01-2026 - 15:19
Objavljeno 21-11-2025 - 13:15