
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62080 is a Cross-Site Request Forgery (CSRF) vulnerability in the Channelize.io Team "Live Shopping & Shoppable Videos For WooCommerce" WordPress plugin. It affects all versions through 2.2.0 and was reported by researcher Muhammad Nur Ibnu Hubab on October 27, 2025, then published by Patchstack on December 31, 2025. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Patchstack (Patchstack).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery) and stems from missing or insufficient CSRF token validation on one or more plugin actions within the WooCommerce live shopping plugin. An unauthenticated attacker can craft a malicious web page or link that, when visited by an authenticated WordPress user (e.g., a shop administrator), triggers unauthorized state-changing requests on the target site without the victim's knowledge. No authentication is required on the attacker's side, but successful exploitation depends on a privileged user interacting with attacker-controlled content (Patchstack).
Successful exploitation allows an attacker to force authenticated users — potentially administrators — to perform unwanted actions on the affected WooCommerce site, such as modifying plugin settings or live shopping configurations. The impact is limited to integrity (no confidentiality or availability impact per the CVSS score), but actions taken under an administrator's session could indirectly affect site content or e-commerce operations. The vulnerability is classified under OWASP Top 10 A1: Broken Access Control (Patchstack).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is extremely low at 0.000140, indicating a very low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack rates its priority as "Low" and notes the issue is unlikely to be actively exploited, though CSRF vulnerabilities of this type are sometimes used in mass-exploit campaigns targeting WordPress plugins (Patchstack).
live-shopping-video-streams) in WordPress access logs originating from unusual referrers or external domains.Referer headers pointing to external or unknown domains.As of the disclosure date, no official patch has been released by the plugin developer (Channelize.io Team), and no patched version is available. Site administrators should consider deactivating and removing the plugin until a fix is provided. As a workaround, restricting access to the WordPress admin panel via IP allowlisting and ensuring administrators avoid clicking unsolicited links while logged in can reduce exposure. Patchstack customers received early warning and virtual patching coverage as of December 31, 2025 (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."