CVE-2025-1912
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 918
Summary
CVE-2025-1912: The WooCommerce Import Export Product CSV Suite plugin for WordPress, versions up to 2.5.0, suffers from a Server-Side Request Forgery vulnerability in the validate_file() function. This issue grants authenticated attackers, possessing Administrator-level access or higher, the ability to initiate web requests to unintended destinations from within the application. Consequently, sensitive information can be queried or modified from linked internal services.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.