PT-2025-21987 · Woocommerce · Japanized For Woocommerce

Lucky_Buddy

·

Published

2025-05-19

·

Updated

2025-05-19

·

CVE-2025-48284

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Japanized For WooCommerce versions 2.6.40 and earlier
Description: A Cross-Site Request Forgery (CSRF) issue affects the software, allowing unauthorized actions to be performed on behalf of a user. This issue can be exploited by tricking a user into performing an unintended action on the web application.
Recommendations: For versions 2.6.40 and earlier, update to a version later than 2.6.40 to resolve the issue. As a temporary workaround, consider implementing additional validation checks on requests to prevent unauthorized actions. Restrict access to sensitive functionality to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-48284

Affected Products

Japanized For Woocommerce