PT-2025-33228 · WordPress · Yith Woocommerce Popup

Nguyen Xuan Chien

·

Published

2025-08-14

·

Updated

2025-08-14

·

CVE-2025-54675

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: YITH WooCommerce Popup versions through 1.48.0
Description: A Cross-Site Request Forgery (CSRF) issue exists in YITH WooCommerce Popup, potentially allowing attackers to perform actions on behalf of authenticated users.
Recommendations: Update YITH WooCommerce Popup to a version later than 1.48.0.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-54675

Affected Products

Yith Woocommerce Popup