<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Holest - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/holest/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 29 Jul 2026 10:18:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/holest/feed.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-10656: WordPress Spreadsheet Price Changer Plugin Missing Authorization Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-07-wordpress-price-changer-cve-2025-10656/</link><pubDate>Wed, 29 Jul 2026 10:18:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-wordpress-price-changer-cve-2025-10656/</guid><description>CVE-2025-10656 describes a Missing Authorization vulnerability in the Spreadsheet Price Changer for WooCommerce and WP E-commerce - Light plugin for WordPress, affecting all versions up to and including 2.4.37, which allows unauthenticated attackers to create new administrator accounts, leading to privilege escalation and potential full control over affected WordPress sites.</description><content:encoded><![CDATA[<p>A critical Missing Authorization vulnerability, tracked as CVE-2025-10656, has been identified in the &quot;Spreadsheet Price Changer for WooCommerce and WP E-commerce - Light&quot; plugin for WordPress. This flaw impacts all versions of the plugin up to and including 2.4.37. The vulnerability resides within the <code>user_filter</code> function, which fails to properly enforce authorization checks. This oversight allows unauthenticated attackers to send specially crafted requests that result in the creation of new administrator accounts on the affected WordPress site. The successful exploitation of this vulnerability grants attackers full administrative control, enabling them to manipulate website content, install malicious plugins, exfiltrate data, or otherwise compromise the integrity and availability of the web application.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An unauthenticated attacker identifies a WordPress site running the vulnerable Spreadsheet Price Changer for WooCommerce and WP E-commerce - Light plugin.</li>
<li>The attacker crafts a malicious HTTP request targeting the <code>user_filter</code> function within the <code>sellingcommander.php</code> file of the plugin.</li>
<li>This request leverages the Missing Authorization vulnerability (CVE-2025-10656) by including parameters designed to register a new user with elevated privileges.</li>
<li>Due to the lack of proper authentication checks, the plugin processes the attacker's request as legitimate.</li>
<li>The vulnerable plugin creates a new administrator account on the WordPress site as specified by the attacker.</li>
<li>The attacker uses the credentials of the newly created administrator account to log into the WordPress dashboard.</li>
<li>With administrative access, the attacker gains full control over the compromised WordPress site.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The successful exploitation of CVE-2025-10656 results in a complete compromise of the affected WordPress site. Attackers gain full administrative control, which can lead to severe consequences including, but not limited to, website defacement, arbitrary code execution (via malicious plugin/theme uploads), data theft, deployment of web shells, or redirection of legitimate users to malicious sites. This vulnerability poses a significant risk to the integrity and availability of the targeted web application and associated data, potentially affecting customers and business operations.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately update the &quot;Spreadsheet Price Changer for WooCommerce and WP E-commerce - Light&quot; plugin to a patched version beyond 2.4.37, or disable and remove the plugin if an update is not available.</li>
<li>Review web server access logs for any suspicious HTTP requests targeting <code>sellingcommander.php</code> or the <code>user_filter</code> function, especially those originating from unusual IP addresses or user agents.</li>
<li>Monitor WordPress user logs for the creation of new administrator accounts that were not legitimately authorized.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>wordpress</category><category>plugin</category><category>web</category><category>cve</category><category>missing-authorization</category><category>privilege-escalation</category></item></channel></rss>