PT-2025-49201 · WordPress · Eprolo Dropshipping

Abhirup Konwar

·

Published

2025-12-05

·

Updated

2025-12-05

·

CVE-2025-12133

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions EPROLO Dropshipping plugin for WordPress versions through 2.3.1
Description The EPROLO Dropshipping plugin for WordPress is susceptible to unauthorized data modification because of a missing capability check. This affects the wp ajax eprolo delete tracking and wp ajax eprolo save tracking data API endpoints. Authenticated attackers with Subscriber-level access or higher can modify and delete tracking data. The vulnerable parameters are not specified.
Recommendations Update the EPROLO Dropshipping plugin to a version beyond 2.3.1.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12133

Affected Products

Eprolo Dropshipping