Kirim.Email WooCommerce Integration Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Kirim.Email WooCommerce Integration plugin for WordPress, affecting all versions through 1.2.9. The vulnerability arises from a lack of nonce validation on the plugin's settings page, allowing unauthenticated attackers to alter the plugin's API credentials and integration settings. Exploitation requires tricking a site administrator into performing an action, such as clicking a link.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in the plugin's settings, including API credentials, potentially allowing for further exploitation or misuse of the integrated services.

Reproduction

To reproduce this vulnerability, an attacker must craft a forged request that exploits the missing nonce validation. This can be done by tricking an administrator into clicking a link that carries the malicious request, perhaps through social engineering or other deceptive means.

Remediation

No known patch is available. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.

Added: Dec 12, 2025, 4:36 AM
Updated: Dec 12, 2025, 4:36 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
1.4
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.