CVE-2025-47462: WordPress Challan plugin <= 3.7.58 - CSRF to Privilege Escalation vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Ohidul Islam Challan allows Privilege Escalation. This issue affects Challan: from n/a through 3.7.58.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in WebAppick Challan webappick-pdf-invoice-for-woocommerce allows Privilege Escalation.This issue affects Challan: from n/a through <= 3.7.58.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47462?
CVE-2025-47462 has a severity rating that may lead to privilege escalation through a Cross-Site Request Forgery (CSRF) attack.
How do I fix CVE-2025-47462?
To fix CVE-2025-47462, you should update the Ohidul Islam Challan or WordPress Challan plugin to version 3.7.58 or later.
What software is affected by CVE-2025-47462?
CVE-2025-47462 affects Ohidul Islam Challan versions up to 3.7.58 and the WordPress Challan plugin up to version 3.7.58.
What type of vulnerability is CVE-2025-47462?
CVE-2025-47462 is a Cross-Site Request Forgery (CSRF) vulnerability that enables privilege escalation.
Can CVE-2025-47462 be exploited remotely?
Yes, CVE-2025-47462 can be exploited remotely by an attacker to escalate privileges.