CVE-2025-39472: WordPress WooCommerce Social Login plugin < 2.8.3 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Request Forgery.This issue affects WooCommerce Social Login: from n/a through < 2.8.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39472?
CVE-2025-39472 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can allow unauthorized actions to be performed on behalf of users.
How do I fix CVE-2025-39472?
To fix CVE-2025-39472, update the WPWeb WooCommerce Social Login plugin to version 2.8.3 or later.
What versions of WPWeb WooCommerce Social Login are affected by CVE-2025-39472?
CVE-2025-39472 affects all versions of WPWeb WooCommerce Social Login up to and including version 2.8.2.
What impact does CVE-2025-39472 have on users?
CVE-2025-39472 can allow attackers to perform unauthorized actions on behalf of authenticated users, potentially compromising user accounts.
Is there a patch available for CVE-2025-39472?
Yes, a patch is available in the updated version of WPWeb WooCommerce Social Login, specifically version 2.8.3 and later.