CVE-2025-64290: WordPress Premmerce Product Search for WooCommerce plugin <= 2.2.4 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows Cross Site Request Forgery.This issue affects Premmerce Product Search for WooCommerce: from n/a through <= 2.2.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64290?
CVE-2025-64290 is classified as a Cross-Site Request Forgery (CSRF) vulnerability which can lead to unauthorized actions on behalf of users.
How do I fix CVE-2025-64290?
To mitigate CVE-2025-64290, update the Premmerce Product Search for WooCommerce plugin to version 2.2.5 or higher.
Who is affected by CVE-2025-64290?
CVE-2025-64290 affects users of the Premmerce Product Search for WooCommerce plugin versions from n/a through 2.2.4.
What types of attacks are possible with CVE-2025-64290?
CVE-2025-64290 allows attackers to execute unauthorized requests, potentially leading to data manipulation without user consent.
Is CVE-2025-64290 already exploited in the wild?
There is currently no publicly available information indicating that CVE-2025-64290 has been actively exploited in the wild.