CVE-2025-10656: Holest Spreadsheet Price Changer For Woocommerce And Wp E-Commerce – Light

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes it possible for unauthenticated attackers to create admin accounts.

Affected products

  • Holest Spreadsheet Price Changer For Woocommerce And Wp E-Commerce – Light: up to and including 2.4.37

Published 2026-07-29. Last modified 2026-10-06.