The Woocommerce Multiple Addresses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.7.1. This is due to insufficient restrictions on user meta that can be updated through the save_multiple_shipping_addresses() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.
CVE ID: CVE-2025-4335
CVSS Base Severity: HIGH
CVSS Base Score: 8.8
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor: n3wnormal
Product: Woocommerce Multiple Addresses
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 12.85% (scored less or equal to compared to others)
EPSS Date: 2025-06-04 (when was this score calculated)