CVE-2025-2719 Details
Description
The Swatchly – WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label swatches) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function in versions 1.2.8 to 1.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to 1/true on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny access to legitimate users or be used to set some values to true, such as registration.
A vulnerability exists in the Swatchly – WooCommerce Variation Swatches for Products plugin for WordPress, specifically in versions 1.2.8 to 1.4.0. The issue arises from a lack of proper capability checks in the ajax_dismiss function, allowing authenticated attackers with Subscriber-level access and above to unauthorizedly modify option values on the WordPress site. This could be exploited to introduce errors that disrupt site functionality or to manipulate specific settings, such as enabling user registration.
Users are advised to update the Swatchly – WooCommerce Variation Swatches for Products plugin to version 1.4.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 10, 2025CISA-ADP
Assessed Apr 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Swatchly WooCommerce Variation Swatches for Products | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2025 | New CVE Received | [email protected] |
Volerion