CVE-2025-12130 | WC Vendors Plugin up to 2.6.4 on WordPress delete cross-site request forgery
A vulnerability has been found in WC Vendors Plugin up to 2.6.4 on WordPress and classified as problematic. Impacted is an unknown function of the file /vendor_dashboard/product/delete/. Performing manipulation results in cross-site request forgery.
This vulnerability is cataloged as CVE-2025-12130. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More