PT-2025-50890 · WordPress · Hippoo Mobile App For Woocommerce

Numex

·

Published

2025-12-12

·

Updated

2025-12-12

·

CVE-2025-12655

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hippoo Mobile App for WooCommerce plugin for WordPress versions up to and including 1.7.1
Description The software is susceptible to unauthorized file writing due to a missing authorization check. The REST API endpoint /wp-json/hippoo/v1/wc/token/save callback/{token id} is registered with permission callback => ' return true', which permits unauthenticated access. This allows attackers to write arbitrary JSON content to the server's publicly accessible upload directory via the vulnerable endpoint. The token id is a variable within the API endpoint.
Recommendations Update the Hippoo Mobile App for WooCommerce plugin for WordPress to a version later than 1.7.1.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12655

Affected Products

Hippoo Mobile App For Woocommerce