Description
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for WooCommerce and QuickBooks wp-woocommerce-quickbooks allows Cross Site Request Forgery.This issue affects Integration for WooCommerce and QuickBooks: from n/a through <= 1.3.1.
Published: 2025-04-16
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE-2025-39600 describes a Cross-Site Request Forgery vulnerability in CRM Perks Integration for WooCommerce and QuickBooks plugin versions up to 1.3.1. The flaw allows an attacker to trick a logged‑in WordPress user into sending forged requests that perform privileged actions through the plugin, potentially leading to unauthorized data changes in the WooCommerce store or QuickBooks integration. This issue is rooted in missing proper CSRF protection, as identified by CWE-352, and can be leveraged to carry out unauthorized operations on behalf of the authenticated user.

Affected Systems

Affected systems include WordPress sites running the CRM Perks Integration for WooCommerce and QuickBooks plugin at any version ≤ 1.3.1. No other vendors or product lineages are listed in the CVE data, and the vulnerability is triggered via the web front‑end when the plugin processes incoming requests without sufficient nonce validation.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate impact, and the EPSS score of < 1 % suggests a very low likelihood of exploitation in the wild; the vulnerability is not listed in the CISA KEV catalog. Based on typical CSRF mechanics, the attack vector is inferred to be remote and relies on a victim’s authenticated browser session to submit malicious requests. Attackers would need to lure or trick users into visiting crafted URLs or loading malicious content that emits requests to the plugin’s endpoints, exploiting the missing CSRF checks.

Generated by OpenCVE AI on April 30, 2026 at 22:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the CRM Perks Integration for WooCommerce and QuickBooks plugin to a version newer than 1.3.1, which contains the CSRF fix.
  • If an upgrade is not immediately possible, deactivate the plugin to eliminate the unsecured endpoints from the front‑end.
  • Add WordPress nonce checks to any remaining plugin endpoints that process sensitive actions, or enable built‑in CSRF defenses in WordPress to validate form submissions.

Generated by OpenCVE AI on April 30, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11279 Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for WooCommerce and QuickBooks allows Cross Site Request Forgery. This issue affects Integration for WooCommerce and QuickBooks: from n/a through 1.3.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for WooCommerce and QuickBooks allows Cross Site Request Forgery. This issue affects Integration for WooCommerce and QuickBooks: from n/a through 1.3.1. Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for WooCommerce and QuickBooks wp-woocommerce-quickbooks allows Cross Site Request Forgery.This issue affects Integration for WooCommerce and QuickBooks: from n/a through <= 1.3.1.
Title WordPress Integration for WooCommerce and QuickBooks <= 1.3.1 - Cross Site Request Forgery (CSRF) Vulnerability WordPress Integration for WooCommerce and QuickBooks plugin <= 1.3.1 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 16 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Apr 2025 12:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for WooCommerce and QuickBooks allows Cross Site Request Forgery. This issue affects Integration for WooCommerce and QuickBooks: from n/a through 1.3.1.
Title WordPress Integration for WooCommerce and QuickBooks <= 1.3.1 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:07:58.625Z

Reserved: 2025-04-16T06:27:02.093Z

Link: CVE-2025-39600

cve-icon Vulnrichment

Updated: 2025-04-16T13:52:16.213Z

cve-icon NVD

Status : Deferred

Published: 2025-04-16T13:15:52.653

Modified: 2026-04-23T15:29:52.030

Link: CVE-2025-39600

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T23:00:04Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)