CVE-2025-62945
8.8Eduard Pinuaga Linares · Did Prestashop Display
A Cross-Site Request Forgery vulnerability in the Did Prestashop Display plugin allows for stored Cross-Site Scripting.
Executive summary
A Cross-Site Request Forgery vulnerability in the Did Prestashop Display plugin for WordPress may allow unauthenticated attackers to perform unauthorized actions and inject malicious scripts.
Vulnerability
This vulnerability is a Cross-Site Request Forgery (CWE-352) that enables stored Cross-Site Scripting. An unauthenticated attacker can trick a logged-in administrator into performing actions that lead to the execution of arbitrary script code in the context of the user session.
Business impact
The exploitation of this flaw can lead to unauthorized administrative actions, session hijacking, or the theft of sensitive data through script execution. Given the CVSS score of 8.8, this vulnerability poses a high risk to the integrity and confidentiality of the WordPress environment, potentially allowing attackers to compromise the entire site.
Remediation
Immediate Action: Since a specific patch is not currently confirmed, users should immediately deactivate and uninstall the Did Prestashop Display plugin until a secure update is released by the vendor.
Proactive Monitoring: Review administrative access logs for suspicious activity or unauthorized changes to plugin settings and site configurations.
Compensating Controls: Implement a Web Application Firewall (WAF) with robust CSRF protection rules to block requests that lack valid anti-forgery tokens.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS severity and the potential for cross-site scripting, organizations currently running the Did Prestashop Display plugin must prioritize its removal. Security teams should monitor the developer's official channels for a security release and verify that any future versions have addressed the underlying CSRF flaw before re-enabling the component.
Sources
Originally found and disclosed by Nguyen Xuan Chien | Patchstack Bug Bounty Program, per the CVE Program record.