CVE-2025-22731
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 15, 2025
CWE ID 352
Summary
CVE-2025-22731 represents a Cross-Site Request Forgery (CSRF) vulnerability in the Build Private Store plugin for Woocommerce, versions n/a through 1.0. This issue enables an attacker to submit unintended commands in the context of an unsuspecting user, potentially leading to data manipulation or unauthorized actions within the affected e-commerce platform.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.