← Back to browse · API

CVE-2025-48123

Severity
CRITICAL
CVSS
10.0
EPSS
0.00399
Risk score
40.14
CISA KEV
No
PoC
No
Published
2025-06-09
Modified
2026-04-28
First seen
2026-08-07
Aliases
EUVD-2025-17525, GHSA-M6CV-FWF2-4V2W
Products
Holest Engineering:Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light 0 ≤2.4.37
Sources
euvd EUVD-2025-17525

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows Code Injection.This issue affects Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light: from n/a through <= 2.4.37.

References