The wModes – Catalog Mode, Product Pricing, Enquiry Forms & Promotions plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.2.2. This is due to the plugin not properly verifying that a user is authorized to access sensitive information via the AJAX endpoint. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive information including user emails, usernames, roles, capabilities, and WooCommerce data such as products and payment methods.
History

Wed, 19 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Sundayfanz
Sundayfanz wmodes
Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Sundayfanz
Sundayfanz wmodes
Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress

Tue, 18 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Nov 2025 09:45:00 +0000

Type Values Removed Values Added
Description The wModes – Catalog Mode, Product Pricing, Enquiry Forms & Promotions plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.2.2. This is due to the plugin not properly verifying that a user is authorized to access sensitive information via the AJAX endpoint. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive information including user emails, usernames, roles, capabilities, and WooCommerce data such as products and payment methods.
Title wModes – Catalog Mode, Product Pricing, Enquiry Forms & Promotions | for WooCommerce <= 1.2.2 - Missing Authorization to Sensitive Information Disclosure
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-11-18T09:27:39.489Z

Updated: 2025-11-18T21:10:14.550Z

Reserved: 2025-11-03T18:30:22.794Z

Link: CVE-2025-12639

cve-icon Vulnrichment

Updated: 2025-11-18T21:10:11.749Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-18T10:15:48.137

Modified: 2025-11-18T14:06:29.817

Link: CVE-2025-12639

cve-icon Redhat

No data.