Description
The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.1. This is due to a missing capability check on the admin_init hook that executes wp_cache_flush(). This makes it possible for unauthenticated attackers to flush the site's object cache via forged requests, potentially degrading site performance.
Problem types
Product status
* (semver)
Timeline
| 2025-11-24: | Vendor Notified |
| 2025-11-26: | Disclosed |
Credits
Abhirup Konwar
References
www.wordfence.com/...-ffa4-40f4-b969-1153192c52d6?source=cve
plugins.trac.wordpress.org/...trunk/admin/admin-ui-setup.php
plugins.trac.wordpress.org/...2.3.1/admin/admin-ui-setup.php
plugins.trac.wordpress.org/...commerce&sfp_email=&sfph_mail=