CVE-2025-39559: WordPress Bring Fraktguiden for WooCommerce plugin <= 1.11.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in Eivin Landa Bring Fraktguiden for WooCommerce bring-fraktguiden-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bring Fraktguiden for WooCommerce: from n/a through <= 1.11.4.
Security readout for executives and security teams
Plain-English summary
CVE-2025-39559 affects the Bring Fraktguiden for WooCommerce WordPress plugin through version 1.11.4. It is a broken access control issue that may let a logged-in user access information they should not see. The CVSS score is 6.5, mainly due to potential confidentiality impact. No active exploitation is indicated in the provided sources.
Executive priority
Treat this as a medium-priority confidentiality risk for affected WooCommerce sites. Prioritize stores with many user accounts, sensitive order data, or shared staff access. The main business concern is unauthorized data exposure, not system takeover, based on the provided CVSS details.
Technical view
The issue is classified as CWE-862, Missing Authorization. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating network access, low complexity, required low privileges, no user interaction, and high confidentiality impact. Affected product: Eivin Landa Bring Fraktguiden for WooCommerce, package bring-fraktguiden-for-woocommerce, versions through 1.11.4.
Likely exposure
Exposure is limited to WordPress/WooCommerce sites with Bring Fraktguiden for WooCommerce installed at version 1.11.4 or earlier. The CVSS vector indicates an attacker needs some authenticated access, reducing broad internet risk but still relevant for sites with customer, subscriber, or staff accounts.
Exploitation context
The provided sources do not report public exploit code or active exploitation, and the CVE is not listed as KEV. The risk is unauthorized access to confidential data from within an authenticated WordPress context. Details about exact vulnerable functions or data exposed are not provided in the source bundle.
Researcher notes
Evidence is limited to the CVE record and Patchstack entry. The vulnerability type is missing authorization, but the provided data does not name endpoints, capabilities, affected parameters, exploit details, or a confirmed fixed version. Avoid assuming unauthenticated exploitation; CVSS specifies PR:L.
Mitigation direction
Inventory WordPress sites for the Bring Fraktguiden for WooCommerce plugin.
Identify any installations running version 1.11.4 or earlier.
Check vendor, WordPress plugin, and Patchstack guidance for a fixed version or workaround.
Restrict unnecessary WordPress user accounts until remediation is confirmed.
Review logs for unusual authenticated access to plugin-related functionality.
Validation and detection
Confirm plugin name and version from WordPress admin or asset inventory.
Compare installed versions against the affected range: through 1.11.4.
Verify whether vendor or Patchstack lists a patched release.
Review WordPress roles with access to WooCommerce or plugin functions.
Document sites where no fixed version or vendor mitigation is available.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-862: Authorization and privilege behavior lookup
Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-862 · source CWE mapping
Missing Authorization
Missing Authorization represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.