CVE-2025-22731

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 15, 2025
CWE ID 352

Summary

CVE-2025-22731 represents a Cross-Site Request Forgery (CSRF) vulnerability in the Build Private Store plugin for Woocommerce, versions n/a through 1.0. This issue enables an attacker to submit unintended commands in the context of an unsuspecting user, potentially leading to data manipulation or unauthorized actions within the affected e-commerce platform.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share