Holest Engineering Selling Commander for WooCommerce Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in the Holest Engineering Selling Commander for WooCommerce plugin, specifically in versions through 1.2.46. This vulnerability allows incorrect privilege assignment, enabling users to gain elevated rights within the application.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing users to gain elevated rights or access within the WooCommerce environment.

Added: Nov 6, 2025, 5:45 PM
Updated: Nov 6, 2025, 8:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.