Description
Cross-Site Request Forgery (CSRF) vulnerability in SOFTAGON WooCommerce Products without featured images woocommerce-products-without-featured-images allows Reflected XSS.This issue affects WooCommerce Products without featured images: from n/a through <= 0.1.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a CSRF condition that allows an attacker to inject arbitrary JavaScript into the response of a reflected XSS sink. When an authenticated attacker tricks the victim into submitting a crafted request, the plugin reflects unsanitized user input back into the page, enabling script execution that can steal cookies, deface the site, or perform actions on behalf of the victim. The weakness maps to CWE‑352. The impact is the compromise of confidentiality, integrity, and availability of the website and any logged‑in users.

Affected Systems

The flaw affects the WordPress plugin Softagon WooCommerce Products without Featured Images, version 0.1 and all prior releases. It is used on sites running WordPress with WooCommerce, regardless of the specific themes or other plugins installed.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, but the EPSS score is below 1%, suggesting very low exploitation probability at this time. The vulnerability is not listed in the CISA KEV catalog, so no known large‑scale exploitation has been reported. The likely attack path requires the attacker to obtain a victim’s browser session or trick a legitimate user into visiting a crafted URL, which is inferred from the CSRF nature of the flaw. Given these conditions, the risk is moderate to high if the plugin is actively used, but the actual likelihood of exploitation remains low unless automated or widespread CSRF campaigns target it.

Generated by OpenCVE AI on May 1, 2026 at 09:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WooCommerce Products without Featured Images to the latest version that removes the reflected XSS vulnerability
  • If an upgrade is infeasible, disable or delete the plugin to eliminate the attack surface
  • For custom development, enforce proper CSRF tokens or nonces on all form submissions to prevent unauthorized requests

Generated by OpenCVE AI on May 1, 2026 at 09:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11674 Cross-Site Request Forgery (CSRF) vulnerability in SOFTAGON WooCommerce Products without featured images allows Reflected XSS. This issue affects WooCommerce Products without featured images: from n/a through 0.1.
History

Wed, 29 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in SOFTAGON WooCommerce Products without featured images allows Reflected XSS. This issue affects WooCommerce Products without featured images: from n/a through 0.1. Cross-Site Request Forgery (CSRF) vulnerability in SOFTAGON WooCommerce Products without featured images woocommerce-products-without-featured-images allows Reflected XSS.This issue affects WooCommerce Products without featured images: from n/a through <= 0.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in SOFTAGON WooCommerce Products without featured images allows Reflected XSS. This issue affects WooCommerce Products without featured images: from n/a through 0.1.
Title WordPress WooCommerce Products without featured images Plugin <= 0.1 - CSRF to Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:51:54.970Z

Reserved: 2025-04-09T11:19:50.088Z

Link: CVE-2025-32545

cve-icon Vulnrichment

Updated: 2025-04-17T18:06:26.908Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:42.833

Modified: 2026-04-29T10:16:46.273

Link: CVE-2025-32545

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T09:45:07Z

Weaknesses