PT-2025-46277 · WordPress · Usb Qr Code Scanner For Woocommerce

Dayea Song

·

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2025-12588

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions USB Qr Code Scanner For Woocommerce plugin for WordPress versions prior to 1.0.1
Description The USB Qr Code Scanner For Woocommerce plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF). This is a result of a lack of nonce validation on the settings page. An unauthenticated attacker could potentially update the plugin’s settings by forging a request, provided they can trick an administrator into performing an action, such as clicking a malicious link.
Recommendations Update the USB Qr Code Scanner For Woocommerce plugin for WordPress to version 1.0.1 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-12588

Affected Products

Usb Qr Code Scanner For Woocommerce