CVE-2025-29006: WordPress Direct Checkout for WooCommerce Lite <= 1.0.3 - Broken Access Control Vulnerability

5.3 CVSS

Description

Missing Authorization vulnerability in centangle Direct Checkout for WooCommerce Lite allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Direct Checkout for WooCommerce Lite: from n/a through 1.0.3.

Classification

CVE ID: CVE-2025-29006

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.3

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Problem Types

CWE-862 Missing Authorization

Affected Products

Vendor: centangle

Product: Direct Checkout for WooCommerce Lite

References

https://nvd.nist.gov/vuln/detail/CVE-2025-29006
https://patchstack.com/database/wordpress/plugin/woo-direct-checkout-lite/vulnerability/wordpress-direct-checkout-for-woocommerce-lite-1-0-3-broken-access-control-vulnerability?_s_id=cve

Timeline