
CVE-2025-14357 The Mega Store Woocommerce theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the setup_widgets() function in… https://www.cve.org/CVERecord?id=CVE-2025-14357
Post summary
The Mega Store WooCommerce WordPress theme has been disclosed to contain a missing capability check in setup_widgets(), enabling unauthorized data modifications. No evidence of exploitation or mitigation is mentioned.
