PT-2025-36216 · Woocommerce · Woocommerce Gifts

·

CVE-2025-58878

·

Published

2025-09-05

·

Updated

2025-09-05

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Woocommerce Gifts Product versions through 1.0.0
Description The software contains a Cross-Site Request Forgery (CSRF) flaw. This allows attackers to perform actions on behalf of authenticated users without their knowledge.
Recommendations Apply updates to versions prior to 1.0.0.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-58878

Affected Products

Woocommerce Gifts