CVE-2025-26568

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Feb 13, 2025
CWE ID 352

Summary

CVE-2025-26568 is a newly identified vulnerability that affects the Easy Amazon Product Information plugin, versions n/a through 4.0.1. This issue combines two risks: Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS). An attacker can exploit the CSRF vulnerability to force unintended actions from a user, while the Stored XSS allows the injection of malicious scripts into web pages viewed by other users. Successful exploitation of this vulnerability could result in compromised user sessions, data theft, or even site takeover. Users of the affected plugin are advised to upgrade to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share