VYPR
Medium severity4.3NVD Advisory· Published May 7, 2025· Updated Apr 23, 2026

CVE-2025-47451

CVE-2025-47451

Description

Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Product Quantity Dropdown For Woocommerce product-quantity-dropdown-for-woocommerce allows Cross Site Request Forgery.This issue affects Product Quantity Dropdown For Woocommerce: from n/a through <= 1.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF in Product Quantity Dropdown For Woocommerce plugin enables attackers to change plugin settings via a crafted request, requiring user interaction.

The Product Quantity Dropdown For Woocommerce plugin for WordPress (versions up to 1.2) contains a Cross-Site Request Forgery (CSRF) vulnerability. This flaw allows an attacker to perform unauthorized actions on behalf of a privileged user, such as changing plugin settings, by tricking the user into clicking a malicious link or visiting a crafted page [1].

Exploitation requires user interaction; the attacker must convince a logged-in administrator or other high-privilege user to take an action, such as clicking a link or submitting a form. The CSRF vulnerability can be triggered without authentication, but the victim must already be authenticated to the WordPress admin panel [1].

Successful exploitation could allow an attacker to modify plugin settings, potentially leading to further compromise of the WooCommerce store's functionality or data. The vulnerability is considered low severity but is part of mass-exploit campaigns targeting WordPress plugins [1].

The issue is resolved in version 1.3 of the plugin. Users are strongly advised to update immediately. For those unable to update, Patchstack recommends enabling auto-updates for vulnerable plugins or contacting their hosting provider for assistance [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.