CVE-2025-64288: WordPress Premmerce plugin <= 1.3.19 - Cross Site Request Forgery (CSRF) vulnerability
Published Oct 29, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce premmerce allows Cross Site Request Forgery.This issue affects Premmerce: from n/a through <= 1.3.19.
Affected Software
2 affected components
Premmerce Premmerce<=1.3.19
WordPress Premmerce plugin<=1.3.19
Event History
Oct 29, 2025
CVE Published
via MITRE·08:38 AM
Data Sourced
via MITRE·08:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-64288?
CVE-2025-64288 has been classified with a high severity due to its impact on web application security through Cross-Site Request Forgery.
2
How do I fix CVE-2025-64288?
To fix CVE-2025-64288, update the Premmerce software to the latest version beyond 1.3.19.
3
What versions are affected by CVE-2025-64288?
CVE-2025-64288 affects Premmerce versions up to and including 1.3.19.
4
What type of vulnerability is CVE-2025-64288?
CVE-2025-64288 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Is there a workaround for CVE-2025-64288?
While there is no specific workaround, applying the latest security updates is the best mitigation for CVE-2025-64288.