PT-2025-47708 · WordPress · Bigbuy Dropshipping Connector For Woocommerce

Jarno Vos

·

Published

2025-11-21

·

Updated

2025-11-21

·

CVE-2025-12039

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress versions up to and including 2.0.5
Description The software is susceptible to IP Address Spoofing because of inadequate IP address validation and reliance on user-provided HTTP headers for IP address retrieval. This allows unauthenticated attackers to retrieve the output of the phpinfo() function.
Recommendations Update the The BigBuy Dropshipping Connector for WooCommerce plugin to a version later than 2.0.5.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-12039

Affected Products

Bigbuy Dropshipping Connector For Woocommerce