CVE-2023-6625: Gravitymaster Product Enquiry For Woocommerce

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack

Affected products

  • Gravitymaster Product Enquiry For Woocommerce: before 3.1 (fixed in 3.1)

Published 2024-01-22. Last modified 2026-06-17.