External risk intelligence

Spreadsheet Price Changer WooCommerce Plugin Vulnerable to Unauthorized Admin Account Creation.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-10656

This vulnerability exists in a WordPress plugin designed for e-commerce platforms. Such plugins are typically installed on web servers that are intended to be public-facing to facilitate online store operations and customer access, making the attack surface readily reachable from the internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a WordPress plugin used for managing product pricing in WooCommerce and WP E-commerce stores. This issue allows unauthenticated attackers to create new administrator accounts, potentially leading to unauthorized access and control of affected websites. The main concern is confirming relevance and exposure of this plugin within your digital assets.

  • Unauthenticated attackers can create admin accounts.
  • Confirms plugin's presence and potential exposure.
  • Assess and confirm relevance to your business.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending a crafted request to a vulnerable WordPress site. This request targets a specific function within the Spreadsheet Price Changer plugin, which fails to properly check user authorization. Successful exploitation allows an attacker to create a new administrator account, giving them full control over the WordPress site.

  • No authentication required.
  • Triggered via a specific function call.
  • Allows creation of admin accounts.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to create new administrative accounts on a WordPress site that uses the affected plugin. This access could potentially impact the integrity and availability of the website's services and data.

  • Website administrative access at risk.
  • Unauthenticated users could create accounts.
  • Compromised website integrity and availability.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WordPress plugin "Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light" is susceptible to critical vulnerabilities that could allow unauthenticated attackers to create administrative accounts. Responsibility for addressing this likely falls to the team managing the WordPress application and its plugins, often the application owners or a dedicated web platform team. The first practical step is to confirm the presence and reachability of this plugin across your WordPress instances, identify the accountable owner for each, and then prioritize remediation based on business criticality and exposure.

  • Application owners should own the issue.
  • Verify plugin reachability and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Spreadsheet Price Changer plugin used for?

This WordPress plugin is designed to help store owners manage product pricing efficiently within WooCommerce and WP E-commerce environments. It essentially acts as a bulk editing tool, allowing administrators to update price lists through a spreadsheet-like interface rather than manually editing every individual product entry.

What does CWE-863 mean for CVE-2025-10656?

CWE-863 represents a 'Missing Authorization' weakness. In the context of CVE-2025-10656, it means the plugin fails to verify whether a person requesting a change has the appropriate permissions. Because this security check is absent, the plugin performs high-privilege tasks, such as creating new admin accounts, even when the person making the request is not logged in or authorized to do so.

How do attackers trigger this vulnerability?

An attacker triggers this bug by sending a specifically crafted request to the plugin's user_filter function. The vulnerability is not triggered by normal site navigation or standard customer shopping activities. It requires a targeted interaction aimed at that specific function to bypass security controls and create the unauthorized account.

Why should I be concerned about CVE-2025-10656?

According to Halo Surface Signal, this plugin is typically installed on web servers intended to be public-facing to support online store operations. This makes the vulnerability highly reachable from the internet, meaning attackers do not need internal network access to potentially gain administrative control over your WordPress site.

How should I respond to this threat?

Your first step is to perform an inventory of your WordPress instances to confirm if this specific plugin is installed and active. Once you have identified all instances, determine who is responsible for managing each site, assess the business criticality of those assets, and prioritize applying security updates or removing the plugin if a fix is available.

References