CVE-2025-31580: WordPress Ni WooCommerce Product Enquiry plugin <= 4.1.8 - Broken Access Control vulnerability

7.5 CVSS

Description

Missing Authorization vulnerability in Anzar Ahmed Ni WooCommerce Product Enquiry allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Ni WooCommerce Product Enquiry: from n/a through 4.1.8.

Classification

CVE ID: CVE-2025-31580

CVSS Base Severity: HIGH

CVSS Base Score: 7.5

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Problem Types

CWE-862 Missing Authorization

Affected Products

Vendor: Anzar Ahmed

Product: Ni WooCommerce Product Enquiry

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 10.18% (scored less or equal to compared to others)

EPSS Date: 2025-04-20 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-31580
https://patchstack.com/database/wordpress/plugin/ni-woocommerce-product-enquiry/vulnerability/wordpress-ni-woocommerce-product-enquiry-plugin-4-1-8-broken-access-control-vulnerability?_s_id=cve

Timeline