CVE-2025-14971
Last modified
CVE-2025-14971 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the createPartialPayment and cancelPartialPayment functions in all versions up to, and including, 2.8.0. This makes it possible for unauthenticated attackers to create partial payments on any order or cancel any existing partial payment via ID enumeration.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the createPartialPayment and cancelPartialPayment functions in all versions up to, and including, 2.8.0. This makes it possible for unauthenticated attackers to create partial payments on any order or cancel any existing partial payment via ID enumeration.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-14971?
How severe is CVE-2025-14971?
How do I fix CVE-2025-14971?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-14965A vulnerability was found in 1541492390c yougou-mall up to 0…5.5
- CVE-2025-14966A vulnerability was determined in FastAdmin up to 1.7.0.2025…7.2
- CVE-2025-14967A vulnerability was identified in itsourcecode Student Manag…9.8
- CVE-2025-14968A security flaw has been discovered in code-projects Simple …9.8
- CVE-2025-14969A flaw was found in Hibernate Reactive. When an HTTP endpoin…4.3
- CVE-2025-1497A vulnerability, that could result in Remote Code Execution …9.8
- CVE-2025-14972* Countermeasures for DPA within SYMCRYPTO engine on SixG30…4.1
- CVE-2025-14973The Recipe Card Blocks Lite WordPress plugin before 3.4.13 d…6.8
- CVE-2025-14974IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 …7.5
- CVE-2025-14975The Custom Login Page Customizer WordPress plugin before 2.5…8.1
- CVE-2025-14976The User Registration & Membership – Custom Registration For…5.4
- CVE-2025-14977The Dokan: AI Powered WooCommerce Multivendor Marketplace So…8.1
Are you affected by CVE-2025-14971?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
