CVE-2025-12655: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-12655 is an arbitrary file write vulnerability in the Hippoo Mobile App for WooCommerce plugin for WordPress, caused by a missing authorization check on a REST API endpoint. It affects all versions of the plugin up to and including 1.7.1. The vulnerability was published on December 12, 2025, and was assigned by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is a missing authorization check (CWE-862) on the REST API endpoint /wp-json/hippoo/v1/wc/token/save_callback/{token_id}, which is registered with permission_callback => '__return_true'. This WordPress callback unconditionally grants access to any caller, effectively making the endpoint publicly accessible without authentication. An unauthenticated attacker can send a crafted HTTP request to this endpoint to write arbitrary JSON content to the server's publicly accessible upload directory. Source code references confirm the vulnerable logic in app/web_api.php and app/utils.php of the plugin (Wordfence, WordPress Trac).

Impact

Successful exploitation allows unauthenticated attackers to write arbitrary JSON files to the server's publicly accessible upload directory, which can be used for website defacement or to stage further attacks. While the direct impact is limited to integrity (no direct confidentiality or availability impact per the CVSS score), written files in a public directory could be leveraged for subsequent exploitation, such as serving malicious content to site visitors or chaining with other vulnerabilities. The scope is limited to WordPress sites running the affected plugin versions (Wordfence, Red Hat CVE).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-12655 as of the available data. The EPSS score is approximately 0.048%, indicating a low probability of exploitation in the near term. The vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Hippoo Mobile App for WooCommerce plugin (versions ≤ 1.7.1) using tools like WPScan, Shodan, or by checking /wp-content/plugins/hippoo/ for plugin presence.
  2. Identify the vulnerable endpoint: Confirm the REST API endpoint is accessible by sending a GET or OPTIONS request to /wp-json/hippoo/v1/wc/token/save_callback/{token_id} on the target site.
  3. Craft the malicious request: Prepare a POST request to /wp-json/hippoo/v1/wc/token/save_callback/{token_id} with a JSON payload containing the content to be written to the server.
  4. Write arbitrary file: Submit the crafted request without any authentication headers. Due to the permission_callback => '__return_true' misconfiguration, the server accepts and processes the request, writing the attacker-controlled JSON content to the WordPress upload directory.
  5. Access the written file: Retrieve the written file from the publicly accessible upload directory (e.g., /wp-content/uploads/) to confirm successful exploitation or to serve malicious content (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unexpected POST requests to /wp-json/hippoo/v1/wc/token/save_callback/ from unknown or external IP addresses in web server access logs.
  • File System: Unexpected or newly created .json files in the WordPress upload directory (/wp-content/uploads/) with unusual names or content not associated with normal site operations.
  • Logs: Web server access logs showing repeated or automated requests to the Hippoo REST API endpoint, particularly from non-administrative sources or with unusual token_id values.
  • Process: No unusual process behavior expected, as exploitation is purely HTTP-based and does not require code execution (Wordfence).

Mitigation and workarounds

Users should update the Hippoo Mobile App for WooCommerce plugin to version 1.7.2 or later, which addresses the missing authorization check. As a temporary workaround, site administrators can disable the plugin until the update is applied, or use a web application firewall (WAF) rule to block unauthenticated requests to the /wp-json/hippoo/v1/wc/token/save_callback/ endpoint. Restricting access to the WordPress REST API for unauthenticated users via server configuration or security plugins can also reduce exposure (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management