CVE-2023-6625

CVE-2023-6625: Product Enquiry for WooCommerce < 3.1 - Arbitrary Enquiry Deletion via CSRF

Vendor Unknown
Product Product Enquiry for WooCommerce
Published January 22, 2024
Last update June 20, 2025

CVSS base score

What the vulnerability does

01Description

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack

Key dates

02Disclosure timeline

January 22, 2024 CVE published
June 20, 2025 Record updated