Description
Cross-Site Request Forgery (CSRF) vulnerability in WP Trio Conditional Shipping for WooCommerce conditional-shipping-for-woocommerce allows Cross Site Request Forgery.This issue affects Conditional Shipping for WooCommerce: from n/a through <= 3.4.0.
Published: 2025-04-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw (CWE‑352) that allows an attacker to cause the plugin to perform actions without the user’s knowledge or consent, potentially modifying shipping rules or related settings. This can compromise data integrity and control over shipping logic, giving an attacker an indirect means to influence order processing and fulfillment.

Affected Systems

WordPress sites that have installed the Conditional Shipping for WooCommerce plugin from WP Trio, version 3.4.0 or earlier. No newer versions are reported to be affected.

Risk and Exploitability

The CVSS score of 6.5 reflects a moderate severity, while the EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA's KEV catalog. Attackers can exploit this flaw by tricking a user into visiting a malicious webpage, where a forged request is sent to the plugin’s endpoints. The likely attack vector involves a user browsing to a malicious page that submits a forged request, but the CVE data does not specify whether the attack requires user authentication; this requirement is an unknown factor and should be treated as uncertain. Because the loss of control over shipping logic can lead to significant operational impact, the potential damage can be substantial if the vulnerability is exploited. The combination of moderate CVSS, very low EPSS, and absence from KEV suggests a low overall likelihood of widespread exploitation but a non‑negligible impact if an attacker can target a specific site.

Generated by OpenCVE AI on May 1, 2026 at 10:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Conditional Shipping for WooCommerce to the latest release that contains the CSRF fix.
  • If an upgrade is not immediately possible, disable or uninstall the plugin to eliminate the attack surface.
  • Ensure that only users with appropriate administrative roles can access the plugin’s configuration interface and enforce session timeouts to reduce the window for potential CSRF exploitation.

Generated by OpenCVE AI on May 1, 2026 at 10:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11307 Cross-Site Request Forgery (CSRF) vulnerability in WP Trio Conditional Shipping for WooCommerce allows Cross Site Request Forgery. This issue affects Conditional Shipping for WooCommerce: from n/a through 3.4.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in WP Trio Conditional Shipping for WooCommerce allows Cross Site Request Forgery. This issue affects Conditional Shipping for WooCommerce: from n/a through 3.4.0. Cross-Site Request Forgery (CSRF) vulnerability in WP Trio Conditional Shipping for WooCommerce conditional-shipping-for-woocommerce allows Cross Site Request Forgery.This issue affects Conditional Shipping for WooCommerce: from n/a through <= 3.4.0.
Title WordPress Conditional Shipping for WooCommerce <= 3.4.0 - Cross Site Request Forgery (CSRF) Vulnerability WordPress Conditional Shipping for WooCommerce plugin <= 3.4.0 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Wed, 16 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Apr 2025 13:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in WP Trio Conditional Shipping for WooCommerce allows Cross Site Request Forgery. This issue affects Conditional Shipping for WooCommerce: from n/a through 3.4.0.
Title WordPress Conditional Shipping for WooCommerce <= 3.4.0 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Wptrio Conditional Shipping For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:34.850Z

Reserved: 2025-04-16T06:25:01.732Z

Link: CVE-2025-39564

cve-icon Vulnrichment

Updated: 2025-04-16T14:57:53.375Z

cve-icon NVD

Status : Deferred

Published: 2025-04-16T13:15:49.117

Modified: 2026-04-23T15:29:47.850

Link: CVE-2025-39564

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T10:15:17Z

Weaknesses