PT-2025-36216 · Woocommerce · Woocommerce Gifts

Mika

·

Published

2025-09-05

·

Updated

2025-09-05

·

CVE-2025-58878

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Woocommerce Gifts Product versions through 1.0.0
Description The software contains a Cross-Site Request Forgery (CSRF) flaw. This allows attackers to perform actions on behalf of authenticated users without their knowledge.
Recommendations Apply updates to versions prior to 1.0.0.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-58878

Affected Products

Woocommerce Gifts