Medium 4.3
2025-03-27< 1.0.8
CVE-2025-30872
Minimum safe version
1.0.8
Update to 1.0.8 or later to address 6 fixable vulnerabilities
CVE-2025-30872
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Product Author for WooCommerce Plugin < 1.0.4 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Product Author for WooCommerce plugin <= 1.0.2 - Sensitive Information Disclosure vulnerability
WordPress Product Author for WooCommerce plugin <= 1.0.2 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability