PT-2025-50862 · Automattic+1 · Woocommerce+1

Published

2025-12-12

·

Updated

2025-12-12

·

CVE-2025-14165

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kirim.Email WooCommerce Integration versions up to and including 1.2.9
Description The Kirim.Email WooCommerce Integration plugin for WordPress is susceptible to Cross-Site Request Forgery due to the absence of nonce validation on the plugin’s settings page. This allows unauthenticated attackers to alter the plugin’s API credentials and integration settings through a forged request, provided they can deceive a site administrator into performing an action, such as clicking a link.
Recommendations Update Kirim.Email WooCommerce Integration to a version newer than 1.2.9.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-14165

Affected Products

Kirim.Email Woocommerce Integration
Woocommerce