PT-2025-43332 · Automattic+1 · Woocommerce+1

0Xd4Rk5Id3

·

Published

2025-10-22

·

Updated

2025-10-22

·

CVE-2025-62005

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions FantasticPlugins SUMO Memberships for WooCommerce versions prior to 7.8.0
Description A Cross-Site Request Forgery (CSRF) issue exists in FantasticPlugins SUMO Memberships for WooCommerce. This allows attackers to perform actions on behalf of authenticated users without their knowledge.
Recommendations Update FantasticPlugins SUMO Memberships for WooCommerce to version 7.8.0 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62005

Affected Products

Sumo Memberships For Woocommerce
Woocommerce