CVE-2025-12375 | Printful Integration for WooCommerce Plugin up to 2.2.11 on WordPress REST API Endpoint download_url server-side request forgery
A vulnerability marked as critical has been reported in Printful Integration for WooCommerce Plugin up to 2.2.11 on WordPress. Affected by this issue is the function download_url of the component REST API Endpoint. This manipulation causes server-side request forgery.
This vulnerability is tracked as CVE-2025-12375. The attack is possible to be carried out remotely. No exploit exists.