Cross-Site Request Forgery Vulnerability in Japanized For WooCommerce by Shohei Tanaka
CVE-2025-48284

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 May 2025

What is CVE-2025-48284?

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Japanized For WooCommerce, developed by Shohei Tanaka. This flaw allows malicious actors to execute unauthorized commands on behalf of authenticated users. It affects all versions up to and including 2.6.40, potentially compromising the integrity of online transactions. Website owners using this plugin should take immediate measures to secure their sites against this vulnerability.

Affected Version(s)

Japanized For WooCommerce <= 2.6.40

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lucky_buddy (Patchstack Alliance)
.