PT-2025-49985 · Marcoingraiti+1 · Actionwear Products Sync

CVE-2025-49350

·

Published

2025-12-06

·

Updated

2025-12-09

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Actionwear products sync versions prior to 2.3.4
Description The Actionwear products sync plugin for WordPress contains a missing authorization flaw due to an incorrectly configured access control security level. This occurs because of a missing capability check within a function, allowing authenticated users with subscriber-level access or higher to perform unauthorized actions.
Recommendations Update Actionwear products sync to version 2.3.4 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-49350

Affected Products

Actionwear Products Sync