Description
Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH WooCommerce Popup yith-woocommerce-popup allows Cross Site Request Forgery.This issue affects YITH WooCommerce Popup: from n/a through <= 1.48.0.
Published: 2025-08-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic Cross Site Request Forgery flaw in the YITH WooCommerce Popup WordPress plugin. It allows an attacker who tricks an authenticated user or an administrator into visiting a crafted link or form to perform unauthorized actions on behalf of that victim. The flaw does not lead to remote code execution or direct data exfiltration, but it can cause unwanted changes to site configuration, popup settings, or other plugin behavior. The weakness is identified as CWE-352.

Affected Systems

WordPress sites installing YITHEMES’ YITH WooCommerce Popup plugin with a version number from the earliest release through 1.48.0 are affected. The default package has no explicit lower bound in the vendor information, so any installation with a version equal to or less than 1.48.0 is potentially vulnerable.

Risk and Exploitability

The CVSS score of 4.3 classifies the flaw as moderate in severity. The EPSS score of <1% indicates a very low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog, further reducing the risk posture. Likely exploitation requires a user to be authenticated to the site and to click a malicious link or submit a crafted form in the browser, so standard web‑browser interaction is the inferred attack vector.

Generated by OpenCVE AI on April 30, 2026 at 09:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade YITH WooCommerce Popup to the latest version (1.48.1 or later) that removes the CSRF issue.
  • If an upgrade cannot be made immediately, restrict administrative access and enforce strict session management, limiting the number of users with the ability to trigger popup changes.
  • Configure the plugin—or use a security extension such as Wordfence—to add and validate non‑ces or other CSRF tokens on all POST requests that modify popup settings, ensuring that only intentional, authenticated actions are processed.

Generated by OpenCVE AI on April 30, 2026 at 09:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24718 Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH WooCommerce Popup allows Cross Site Request Forgery. This issue affects YITH WooCommerce Popup: from n/a through 1.48.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH WooCommerce Popup allows Cross Site Request Forgery. This issue affects YITH WooCommerce Popup: from n/a through 1.48.0. Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH WooCommerce Popup yith-woocommerce-popup allows Cross Site Request Forgery.This issue affects YITH WooCommerce Popup: from n/a through <= 1.48.0.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Sat, 16 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Yithemes
Yithemes yith Woocommerce Compare
Vendors & Products Wordpress
Wordpress wordpress
Yithemes
Yithemes yith Woocommerce Compare

Thu, 14 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 10:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH WooCommerce Popup allows Cross Site Request Forgery. This issue affects YITH WooCommerce Popup: from n/a through 1.48.0.
Title WordPress YITH WooCommerce Popup Plugin plugin <= 1.48.0 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Yithemes Yith Woocommerce Compare
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:34.120Z

Reserved: 2025-07-28T10:55:38.572Z

Link: CVE-2025-54675

cve-icon Vulnrichment

Updated: 2025-08-14T14:17:34.054Z

cve-icon NVD

Status : Deferred

Published: 2025-08-14T11:15:46.223

Modified: 2026-04-23T15:32:48.133

Link: CVE-2025-54675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T09:15:28Z

Weaknesses