CVE-2025-62061: WordPress Product Catalog Simple plugin <= 1.8.4 - Cross Site Request Forgery (CSRF) vulnerability
Published Oct 22, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in impleCode Product Catalog Simple post-type-x.This issue affects Product Catalog Simple: from n/a through <= 1.8.4.
Affected Software
2 affected components
impleCode Product Catalog Simple<=1.8.4
WordPress Product Catalog Simple<=1.8.4
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62061?
CVE-2025-62061 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2025-62061?
To fix CVE-2025-62061, upgrade the Product Catalog Simple plugin to version 1.8.5 or later.
3
Which versions are affected by CVE-2025-62061?
CVE-2025-62061 affects Product Catalog Simple versions from n/a through 1.8.4.
4
What type of vulnerability is CVE-2025-62061?
CVE-2025-62061 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Who is the vendor for the affected product in CVE-2025-62061?
The vendor for the affected product is impleCode.