PT-2025-47279 · Unknown+1 · Woocommerce+1

Abhirup Konwar

·

Published

2025-11-18

·

Updated

2025-11-18

·

CVE-2025-12392

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress versions through 2.0.22
Description The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is susceptible to unauthorized data modification. This is due to a missing capability check within the handle optin optout() function, allowing unauthenticated attackers to control tracking preferences by opting in and out of tracking.
Recommendations Update the Cryptocurrency Payment Gateway for WooCommerce plugin to a version later than 2.0.22.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12392

Affected Products

Cryptocurrency Payment Gateway For Woocommerce
Woocommerce