What is CVE-2025-10656?
This vulnerability affects the 'Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light' plugin for WordPress, allowing unauthenticated attackers to create admin accounts via the 'user_filter' function. Website owners using this plugin should immediately update to the latest version.
Azərbaycanca: Bu boşluq WordPress üçün 'Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light' plagininə təsir edir və autentifikasiya olunmamış hücumçulara 'user_filter' funksiyası vasitəsilə admin hesabı yaratmağa imkan verir. Plagindən istifadə edən sayt sahibləri dərhal ən son versiyaya yeniləməlidir.
FAQ2
Which WordPress plugin does CVE-2025-10656 affect?
This vulnerability affects the 'Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light' plugin.
What can an unauthenticated attacker do by exploiting CVE-2025-10656?
Unauthenticated attackers can create admin accounts via the 'user_filter' function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.