CVE-2025-54675: WordPress YITH WooCommerce Popup Plugin plugin <= 1.48.0 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH WooCommerce Popup allows Cross Site Request Forgery. This issue affects YITH WooCommerce Popup: from n/a through 1.48.0.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH WooCommerce Popup yith-woocommerce-popup allows Cross Site Request Forgery.This issue affects YITH WooCommerce Popup: from n/a through <= 1.48.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54675?
CVE-2025-54675 is considered a medium severity vulnerability due to its potential to allow unauthorized actions via CSRF.
How do I fix CVE-2025-54675?
To fix CVE-2025-54675, update the YITH WooCommerce Popup plugin to version 1.48.1 or later.
What type of attack does CVE-2025-54675 enable?
CVE-2025-54675 enables Cross-Site Request Forgery (CSRF) attacks, allowing attackers to perform actions on behalf of users.
Which versions of YITH WooCommerce Popup are affected by CVE-2025-54675?
Versions of YITH WooCommerce Popup from n/a up to and including 1.48.0 are affected by CVE-2025-54675.
Who is the vendor for CVE-2025-54675?
The vendor for CVE-2025-54675 is YITH, responsible for the YITH WooCommerce Popup plugin.