CVE-2025-10656: Holest Spreadsheet Price Changer For Woocommerce And Wp E-Commerce – Light
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes it possible for unauthenticated attackers to create admin accounts.
Affected products
- Holest Spreadsheet Price Changer For Woocommerce And Wp E-Commerce – Light: up to and including 2.4.37
Published 2026-07-29. Last modified 2026-10-06.