CVE-2025-6730 – WooCommerce Free Gifts Lite – Unauthenticated Data Modification Vulnerability

CVE ID : CVE-2025-6730

Published : July 29, 2025, 10:15 a.m. | 24 minutes ago

Description : The Bonanza – WooCommerce Free Gifts Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the xlo_optin_call() function in all versions up to, and including, 1.0.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set the opt in status to success.

Severity: 4.3 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Share the Post:

Related Posts