CVE-2025-39472: Wpwebelite Woocommerce Social Login

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Request Forgery.This issue affects WooCommerce Social Login: from n/a through < 2.8.3.

Affected products

  • Wpwebelite Woocommerce Social Login: before 2.8.3 (fixed in 2.8.3)

Published 2025-04-16. Last modified 2026-06-17.