Cross-Site Request Forgery in YITH WooCommerce Popup by YITHEMES
CVE-2025-54675
4.3MEDIUM
What is CVE-2025-54675?
A Cross-Site Request Forgery (CSRF) vulnerability in the YITH WooCommerce Popup plugin can allow unauthorized actions to be performed on behalf of a logged-in user without their consent. This issue affects versions from n/a through 1.48.0, creating a security risk that could lead to compromised account integrity and unauthorized operations by malicious actors.
Affected Version(s)
YITH WooCommerce Popup <= 1.48.0