CVE-2025-48111: WordPress YITH PayPal Express Checkout for WooCommerce plugin <= 1.49.0 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH PayPal Express Checkout for WooCommerce allows Cross Site Request Forgery. This issue affects YITH PayPal Express Checkout for WooCommerce: from n/a through 1.49.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48111?
The severity of CVE-2025-48111 is classified as high due to the potential for unauthorized actions through Cross-Site Request Forgery.
How do I fix CVE-2025-48111?
To fix CVE-2025-48111, update YITH PayPal Express Checkout for WooCommerce to version 1.49.1 or later.
What does CVE-2025-48111 affect?
CVE-2025-48111 affects YITH PayPal Express Checkout for WooCommerce versions up to and including 1.49.0.
What is Cross-Site Request Forgery in the context of CVE-2025-48111?
Cross-Site Request Forgery in CVE-2025-48111 allows attackers to perform actions on behalf of users without their consent.
Who is impacted by CVE-2025-48111?
Users and administrators of YITH PayPal Express Checkout for WooCommerce versions up to 1.49.0 are impacted by CVE-2025-48111.