{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/holest/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2025-10656"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light (\u003c= 2.4.37)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","plugin","web","cve","missing-authorization","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["holest"],"content_html":"\u003cp\u003eA critical Missing Authorization vulnerability, tracked as CVE-2025-10656, has been identified in the \u0026quot;Spreadsheet Price Changer for WooCommerce and WP E-commerce - Light\u0026quot; plugin for WordPress. This flaw impacts all versions of the plugin up to and including 2.4.37. The vulnerability resides within the \u003ccode\u003euser_filter\u003c/code\u003e function, which fails to properly enforce authorization checks. This oversight allows unauthenticated attackers to send specially crafted requests that result in the creation of new administrator accounts on the affected WordPress site. The successful exploitation of this vulnerability grants attackers full administrative control, enabling them to manipulate website content, install malicious plugins, exfiltrate data, or otherwise compromise the integrity and availability of the web application.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a WordPress site running the vulnerable Spreadsheet Price Changer for WooCommerce and WP E-commerce - Light plugin.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP request targeting the \u003ccode\u003euser_filter\u003c/code\u003e function within the \u003ccode\u003esellingcommander.php\u003c/code\u003e file of the plugin.\u003c/li\u003e\n\u003cli\u003eThis request leverages the Missing Authorization vulnerability (CVE-2025-10656) by including parameters designed to register a new user with elevated privileges.\u003c/li\u003e\n\u003cli\u003eDue to the lack of proper authentication checks, the plugin processes the attacker's request as legitimate.\u003c/li\u003e\n\u003cli\u003eThe vulnerable plugin creates a new administrator account on the WordPress site as specified by the attacker.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the credentials of the newly created administrator account to log into the WordPress dashboard.\u003c/li\u003e\n\u003cli\u003eWith administrative access, the attacker gains full control over the compromised WordPress site.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2025-10656 results in a complete compromise of the affected WordPress site. Attackers gain full administrative control, which can lead to severe consequences including, but not limited to, website defacement, arbitrary code execution (via malicious plugin/theme uploads), data theft, deployment of web shells, or redirection of legitimate users to malicious sites. This vulnerability poses a significant risk to the integrity and availability of the targeted web application and associated data, potentially affecting customers and business operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the \u0026quot;Spreadsheet Price Changer for WooCommerce and WP E-commerce - Light\u0026quot; plugin to a patched version beyond 2.4.37, or disable and remove the plugin if an update is not available.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for any suspicious HTTP requests targeting \u003ccode\u003esellingcommander.php\u003c/code\u003e or the \u003ccode\u003euser_filter\u003c/code\u003e function, especially those originating from unusual IP addresses or user agents.\u003c/li\u003e\n\u003cli\u003eMonitor WordPress user logs for the creation of new administrator accounts that were not legitimately authorized.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-29T10:18:10Z","date_published":"2026-07-29T10:18:10Z","id":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-price-changer-cve-2025-10656/","summary":"CVE-2025-10656 describes a Missing Authorization vulnerability in the Spreadsheet Price Changer for WooCommerce and WP E-commerce - Light plugin for WordPress, affecting all versions up to and including 2.4.37, which allows unauthenticated attackers to create new administrator accounts, leading to privilege escalation and potential full control over affected WordPress sites.","title":"CVE-2025-10656: WordPress Spreadsheet Price Changer Plugin Missing Authorization Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-price-changer-cve-2025-10656/"}],"language":"en","title":"CraftedSignal Threat Feed - Holest","version":"https://jsonfeed.org/version/1.1"}