Description
Cross-Site Request Forgery (CSRF) vulnerability in brijrajs WooCommerce Single Page Checkout woo-single-page-checkout allows Cross Site Request Forgery.This issue affects WooCommerce Single Page Checkout: from n/a through <= 1.2.7.
Published: 2025-09-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw that enables an attacker to cause a logged‑in WordPress user to submit a request to the WooCommerce Single Page Checkout plugin without the user’s consent. By exploiting this weakness, an attacker could potentially place unauthorized orders or alter purchase details, compromising the integrity of transaction data within the e‑commerce store.

Affected Systems

The affected product is the WooCommerce Single Page Checkout plugin developed by brijrajs. Versions of the plugin from the initial release up to and including 1.2.7 are affected. The vulnerability exists within the WordPress ecosystem when this plugin is installed and activated.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate level of severity, with the likelihood of exploitation reflected by an EPSS score of less than 1 %. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this flaw by hosting a malicious website that includes a hidden transaction request, persuading an authenticated user to visit the page, or by leveraging social engineering to trigger the request. Because the flaw involves the lack of proper anti‑CSRF protections, no additional authentication beyond the user’s current session is required for the exploitation to succeed.

Generated by OpenCVE AI on April 30, 2026 at 07:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WooCommerce Single Page Checkout plugin to a version newer than 1.2.7 or apply a vendor patch that implements proper non‑ceasing CSRF protection.
  • If an update is not immediately available, restrict or disable the checkout functionality for non‑trusted users, or use a temporary CSRF‑protected form wrapper to add unique tokens to transaction requests.
  • In the interim, configure WordPress to enforce stricter nonce checks on all WooCommerce actions or add a custom security plugin that injects a unique, expiring token into each form that submits transactions.

Generated by OpenCVE AI on April 30, 2026 at 07:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26974 Cross-Site Request Forgery (CSRF) vulnerability in brijrajs WooCommerce Single Page Checkout allows Cross Site Request Forgery. This issue affects WooCommerce Single Page Checkout: from n/a through 1.2.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in brijrajs WooCommerce Single Page Checkout allows Cross Site Request Forgery. This issue affects WooCommerce Single Page Checkout: from n/a through 1.2.7. Cross-Site Request Forgery (CSRF) vulnerability in brijrajs WooCommerce Single Page Checkout woo-single-page-checkout allows Cross Site Request Forgery.This issue affects WooCommerce Single Page Checkout: from n/a through <= 1.2.7.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Mon, 08 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Sep 2025 14:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in brijrajs WooCommerce Single Page Checkout allows Cross Site Request Forgery. This issue affects WooCommerce Single Page Checkout: from n/a through 1.2.7.
Title WordPress WooCommerce Single Page Checkout Plugin <= 1.2.7 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-13T00:18:37.361Z

Reserved: 2025-09-05T10:49:12.187Z

Link: CVE-2025-58804

cve-icon Vulnrichment

Updated: 2025-09-08T15:02:33.926Z

cve-icon NVD

Status : Deferred

Published: 2025-09-05T14:15:50.447

Modified: 2026-04-23T15:33:40.070

Link: CVE-2025-58804

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T07:30:31Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)