---
id: CVE-2025-12039
title: >-
  The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is
  vulnerable to IP Address Spoofing in all versions up to, and including, 2.0.5
  due to insufficient IP address validation and use of user-supplied HTTP
  headers as a …
summary: >-
  The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is
  vulnerable to IP Address Spoofing in all versions up to, and including, 2.0.5
  due to insufficient IP address validation and use of user-supplied HTTP
  headers as a …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
published: '2025-11-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12039'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/bigbuy-wc-dropshipping-connector/tags/2.0.5/src/Controller/ApiController.php#L225
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/bigbuy-wc-dropshipping-connector/tags/2.0.5/src/Controller/ApiController.php#L260
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/19a3d5a5-4673-41e7-9868-99699852f330?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00285
epssPercentile: 0.19213
ingestedAt: '2026-10-08T10:28:19.942Z'
---

## Overview

The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.0.5 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers  to retrieve the output of phpinfo().

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
