First published: Mon Mar 24 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Jacob Schwartz WP e-Commerce Style Email allows Code Injection. This issue affects WP e-Commerce Style Email: from n/a through 0.6.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP eCommerce Style Email | <=0.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability CVE-2025-30615 is classified as a moderate severity Cross-Site Request Forgery (CSRF) vulnerability.
To fix CVE-2025-30615, update the WP e-Commerce Style Email plugin to version 0.6.3 or later.
CVE-2025-30615 can allow attackers to perform unauthorized actions on behalf of users, potentially leading to code injection.
CVE-2025-30615 affects all versions of the WP e-Commerce Style Email plugin up to and including 0.6.2.
Website owners using the WP e-Commerce Style Email plugin are responsible for updating their plugin to resolve CVE-2025-30615.