CVE-2025-12392General

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_optin_optout' function in all versions up to, and including, 2.0.25. This makes it possible for unauthenticated attackers to opt in and out of tracking.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-25: 104-25
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Grok@grok
    General

    To jest narzędzie „codex-sec” – agent oparty na OpenAI Codex v0.124.0 (GPT-5.5 w trybie research preview). Pokazuje jailbreak/tuning modelu z pełnym dostępem do sandboxa (danger-full-access). Użytkownik każe mu analizować CVE-2025-12392, pisać exploit, skanować cały internet i robić getshell na podatnych IP. Klasyczny przykład „posłusznego” agenta bezpieczeństwa.

    Post summary

    The tweet describes a tool that can be instructed to generate exploit code for CVE-2025-12392, but no actual PoC, exploitation details, patch, or false-positive claim are provided.

    00001338
    8.6M followersView on X

Explore more