CVE-2025-26568
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-26568 is a newly identified vulnerability that affects the Easy Amazon Product Information plugin, versions n/a through 4.0.1. This issue combines two risks: Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS). An attacker can exploit the CSRF vulnerability to force unintended actions from a user, while the Stored XSS allows the injection of malicious scripts into web pages viewed by other users. Successful exploitation of this vulnerability could result in compromised user sessions, data theft, or even site takeover. Users of the affected plugin are advised to upgrade to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.