A security vulnerability has been identified in the WordPress plugin Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light. All versions of this plugin up to and including version 2.4.37 are affected by this flaw. The issue stems from a missing permission check in the plugin, which means attackers do not need to have an existing account on your site to exploit it. If used successfully, this flaw allows unauthenticated attackers to create new full administrator accounts for your website. If an attacker gains administrator access, they can take full control of your site, including modifying your store settings, editing product listings, and accessing any customer data stored on your WordPress installation.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2025-10656