216.73.216.233

CVE-2025-1912

· Published 26/03/2025 12:15 · Modified 27/03/2025 16:45

Labels: CVE-2025-1912 2025-03-26CVE-2025-1912CWE-918[email protected]

Essential information

Published
26/03/2025 12:15
Modified
27/03/2025 16:45
Author
Creator
CVSS
7.6 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N

CVSS metrics

Description

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the validate_file() Function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
woocommerce / product import export cpe:2.3:a:woocommerce:product_import_export:*:<2.5.0>*:*:*:*:wordpress:*:*

References