PT-2025-43710 · Unknown+1 · Woocommerce+1

Published

2025-10-25

·

Updated

2025-10-30

·

CVE-2025-12095

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simple Registration for WooCommerce versions prior to 1.5.9
Description The Simple Registration for WooCommerce plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) issue. This occurs because of a lack of nonce validation on the role requests admin page handler located in the includes/display-role-admin.php file. An unauthenticated attacker could potentially approve pending role requests and elevate user privileges by deceiving a site administrator into performing an action, such as clicking a malicious link.
Recommendations Update Simple Registration for WooCommerce to version 1.5.9 or later.

Fix

LPE

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-12095

Affected Products

Simple Registration For Woocommerce
Woocommerce