Arbitrary File Write Vulnerability in Hippoo Mobile App for WooCommerce Plugin by WordPress
CVE-2025-12655
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 December 2025
What is CVE-2025-12655?
The Hippoo Mobile App for WooCommerce plugin for WordPress is susceptible to arbitrary file write due to a critical authorization oversight in its REST API endpoint. All versions up to and including 1.7.1 allow unauthenticated users to access the endpoint /wp-json/hippoo/v1/wc/token/save_callback/{token_id} without any permission checks. This vulnerability enables attackers to write arbitrary JSON content to the server's upload directory, potentially leading to further exploitation of the platform.
Affected Version(s)
Hippoo Mobile App for WooCommerce * <= 1.7.1