Junglewise Threat Intelligence

CVE-2025-11954: Sitemio WISECP Cross-Site Request Forgery

CVE-2025-11954 · Severity: high · CVSS 8 · Published 2026-05-20

Executive brief

WISECP, an automation platform for web hosting and billing services, contains a security flaw that could allow an attacker to trick an authorized user into performing unintended actions. If a logged-in administrator or user visits a malicious website, the attacker could potentially hijack their session to modify system settings, access sensitive customer data, or disrupt business operations. The vendor has not yet responded to reports of this vulnerability, and no official patch is currently available.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in WISECP through version 20022026 due to insufficient validation of request origins. An attacker can exploit this by inducing an authenticated user to visit a specially crafted webpage or click a malicious link while their session is active. Successful exploitation allows the attacker to perform state-changing operations with the privileges of the victim, potentially leading to full system compromise if the victim has administrative rights. The vulnerability is tracked as CWE-352 and has a CVSS base score of 8.0. As of the disclosure date, the vendor has not provided a fix.

Affected products

  • Sitemio Information Technologies Trade Ltd. Co. WISECP through 20022026

Timeline

  • 2026-05-20: disclosed: Vulnerability disclosed by TR-CERT
  • 2026-05-20: advisory: NVD published CVE-2025-11954

References