
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12655 is an arbitrary file write vulnerability in the Hippoo Mobile App for WooCommerce plugin for WordPress, caused by a missing authorization check on a REST API endpoint. It affects all versions of the plugin up to and including 1.7.1. The vulnerability was published on December 12, 2025, and was assigned by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is a missing authorization check (CWE-862) on the REST API endpoint /wp-json/hippoo/v1/wc/token/save_callback/{token_id}, which is registered with permission_callback => '__return_true'. This WordPress callback unconditionally grants access to any caller, effectively making the endpoint publicly accessible without authentication. An unauthenticated attacker can send a crafted HTTP request to this endpoint to write arbitrary JSON content to the server's publicly accessible upload directory. Source code references confirm the vulnerable logic in app/web_api.php and app/utils.php of the plugin (Wordfence, WordPress Trac).
Successful exploitation allows unauthenticated attackers to write arbitrary JSON files to the server's publicly accessible upload directory, which can be used for website defacement or to stage further attacks. While the direct impact is limited to integrity (no direct confidentiality or availability impact per the CVSS score), written files in a public directory could be leveraged for subsequent exploitation, such as serving malicious content to site visitors or chaining with other vulnerabilities. The scope is limited to WordPress sites running the affected plugin versions (Wordfence, Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-12655 as of the available data. The EPSS score is approximately 0.048%, indicating a low probability of exploitation in the near term. The vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Wordfence).
/wp-content/plugins/hippoo/ for plugin presence./wp-json/hippoo/v1/wc/token/save_callback/{token_id} on the target site./wp-json/hippoo/v1/wc/token/save_callback/{token_id} with a JSON payload containing the content to be written to the server.permission_callback => '__return_true' misconfiguration, the server accepts and processes the request, writing the attacker-controlled JSON content to the WordPress upload directory./wp-content/uploads/) to confirm successful exploitation or to serve malicious content (Wordfence, WordPress Trac)./wp-json/hippoo/v1/wc/token/save_callback/ from unknown or external IP addresses in web server access logs..json files in the WordPress upload directory (/wp-content/uploads/) with unusual names or content not associated with normal site operations.token_id values.Users should update the Hippoo Mobile App for WooCommerce plugin to version 1.7.2 or later, which addresses the missing authorization check. As a temporary workaround, site administrators can disable the plugin until the update is applied, or use a web application firewall (WAF) rule to block unauthenticated requests to the /wp-json/hippoo/v1/wc/token/save_callback/ endpoint. Restricting access to the WordPress REST API for unauthenticated users via server configuration or security plugins can also reduce exposure (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."