CVE-2025-12655 - Hippoo Mobile App for WooCommerce <= 1.7.1 - missing authorization to unauthenti...
CVE ID : CVE-2025-12655 Published : Dec. 12, 2025, 7:15 a.m. | 32 minutes ago Description : The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authorization check in all versions up to, and including, 1.7.1. This is due to the REST API endpoint `/wp-json/hippoo/v1/wc/token/save_callback/{token_id}` being registered with `permission_callback => '__return_true'`, which allows unauthenticated access. This makes it possible for unauthenticated attackers to write arbitrary JSON content to the server's publicly accessible upload directory via the vulnerable endpoint. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Source: Telegram CVE Monitor