{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-22T23:01:05.654","vulnerabilities":[{"cve":{"id":"CVE-2025-49287","sourceIdentifier":"audit@patchstack.com","published":"2025-06-06T13:15:44.457","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Feed for WooCommerce: from n/a through <= 2.2.8."},{"lang":"es","value":"La vulnerabilidad de falta de autorización en WebToffee Product Feed for WooCommerce permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta al feed de productos para WooCommerce desde n/d hasta la versión 2.2.8."}],"metrics":{},"weaknesses":[{"source":"audit@patchstack.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://patchstack.com/database/Wordpress/Plugin/webtoffee-product-feed/vulnerability/wordpress-product-feed-for-woocommerce-2-2-8-broken-access-control-vulnerability?_s_id=cve","source":"audit@patchstack.com"}]}}]}