CVE 4.3 MEDIUM

Kirim.Email WooCommerce Integration <= 1.2.9 - Cross-Site Request Forgery to Settings Update_CVE-2025-14165

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Description

The Kirim.Email WooCommerce Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9. This is due to missing nonce validation on the plugin's settings page. This makes it possible for unauthenticated attackers to modify the plugin's API credentials and integration settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Basic Information

ID CVE-2025-14165
Source Wordfence
Published Dec 12, 2025 at 03:20

Affected Product

Vendor developerke
Product Kirim.Email WooCommerce Integration
Version *
Affected Versions developerke Kirim.Email WooCommerce Integration *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.