Description

The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the reset_user_password() REST handler in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to reset the password of arbitrary users, including administrators, thereby gaining administrative access.

INFO

Published Date :

2025-10-03T11:17:10.009Z

Last Modified :

2026-04-08T16:46:14.529Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2025-9286 vulnerability.

Vendors Products
Hancock11
  • Appy Pie Connect For Woocommerce
Woocommerce
  • Woocommerce
Wordpress
  • Wordpress

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact