CVE-2025-49265 PUBLISHED

WordPress Membership For WooCommerce plugin <= 2.8.1 - Broken Access Control Vulnerability

Assigner: Patchstack
Reserved: 04.06.2025 Published: 09.06.2025 Updated: 01.04.2026

Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Membership For WooCommerce: from n/a through <= 2.8.1.

Product Status

Vendor WP Swings
Product Membership For WooCommerce
Versions Default: unaffected
  • affected from 0 to 2.8.1 (incl.)

Credits

  • timomangcut | Patchstack Bug Bounty Program finder

References

Problem Types

  • Missing Authorization CWE

Impacts

  • Accessing Functionality Not Properly Constrained by ACLs