CVE-2025-62890: WordPress Premmerce Brands for WooCommerce plugin <= 1.2.13 - Cross Site Request Forgery (CSRF) vulnerability
Published Oct 27, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Brands for WooCommerce premmerce-woocommerce-brands allows Cross Site Request Forgery.This issue affects Premmerce Brands for WooCommerce: from n/a through <= 1.2.13.
Affected Software
1 affected component
Premmerce Premmerce Brands for WooCommerce<=1.2.13
Event History
Oct 27, 2025
CVE Published
via MITRE·01:33 AM
Data Sourced
via MITRE·01:33 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Nov 30, 58290
Event
via MITRE·07:45 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-62890?
CVE-2025-62890 is a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2025-62890?
To fix CVE-2025-62890, update the Premmerce Brands for WooCommerce plugin to the latest version beyond 1.2.13.
3
What are the consequences of CVE-2025-62890?
Exploitation of CVE-2025-62890 could allow attackers to perform unauthorized actions on behalf of users.
4
Which versions of Premmerce Brands for WooCommerce are affected by CVE-2025-62890?
CVE-2025-62890 affects all versions up to and including Premmerce Brands for WooCommerce version 1.2.13.
5
Is CVE-2025-62890 patched in newer versions?
Yes, CVE-2025-62890 has been patched in versions of Premmerce Brands for WooCommerce released after 1.2.13.