---
id: CVE-2025-9286
title: >-
  The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to
  Privilege Escalation due to missing authorization within the
  reset_user_password() REST handler in all versions up to, and including, 1.1.2
summary: >-
  The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to
  Privilege Escalation due to missing authorization within the
  reset_user_password() REST handler in all versions up to, and including,
  1.1.2. This makes it possibl…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-620
published: '2025-10-03'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9286'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/appy-pie-connect-for-woocommerce/trunk/connect-woocommerce-rest-api.php
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3385150/'
    label: security@wordfence.com
  - url: 'https://wordpress.org/plugins/appy-pie-connect-for-woocommerce/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/36fb5b8d-1ea4-45c2-8639-b229efdb57db?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - exploit-available
epss: 0.00467
epssPercentile: 0.38104
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/Nxploited/CVE-2025-9286'
  checkedAt: '2026-09-30T23:30:07.497Z'
exploitAvailable: true
ingestedAt: '2026-09-30T23:29:32.414Z'
---

## Overview

The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the reset_user_password() REST handler in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to reset the password of arbitrary users, including administrators, thereby gaining administrative access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
