CVE-2025-54041: WordPress Wallet System for WooCommerce plugin <= 2.6.7 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce allows Cross Site Request Forgery. This issue affects Wallet System for WooCommerce: from n/a through 2.6.7.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Cross Site Request Forgery.This issue affects Wallet System for WooCommerce: from n/a through <= 2.6.7.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54041?
CVE-2025-54041 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2025-54041?
To mitigate CVE-2025-54041, update the WP Swings Wallet System for WooCommerce to version 2.6.8 or later.
Which versions of the Wallet System for WooCommerce are affected by CVE-2025-54041?
CVE-2025-54041 affects all versions of the Wallet System for WooCommerce up to and including version 2.6.7.
What type of attack can CVE-2025-54041 enable?
CVE-2025-54041 allows attackers to perform unauthorized actions on behalf of users without their consent.
Is CVE-2025-54041 a critical security vulnerability?
While CVE-2025-54041 poses a significant security risk due to its CSRF nature, its criticality depends on the context and deployment.