CVE-2025-12584: Quick View for WooCommerce <= 2.2.17 - Unauthenticated Private Product Disclosure
The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.17 via the 'wqvpopupcontent' AJAX endpoint due to insufficient restrictions on which products can be included. This makes it possible for unauthenticated attackers to extract data from private products that they should not have access to.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12584?
CVE-2025-12584 is classified as a high severity vulnerability due to information exposure risks.
How do I fix CVE-2025-12584?
To fix CVE-2025-12584, update the Quick View for WooCommerce plugin to version 2.2.18 or later.
Who is affected by CVE-2025-12584?
All versions of the Quick View for WooCommerce plugin for WordPress up to and including 2.2.17 are affected by CVE-2025-12584.
What type of vulnerability is CVE-2025-12584?
CVE-2025-12584 is an information exposure vulnerability that allows unauthorized access to product data.
Can unauthorized users exploit CVE-2025-12584?
Yes, unauthorized users can exploit CVE-2025-12584 through the 'wqv_popup_content' AJAX endpoint.