CVE-2025-1705
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2025-1705 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the tagDiv Composer plugin for WordPress. Versions up to 5.3 are susceptible to this issue. The root cause lies in the lack of proper nonce validation within the 'td_ajax_get_views' AJAX action. This flaw enables unauthenticated attackers to insert malicious web scripts into a site by tricking a site administrator into performing a specific action, such as clicking on a malicious link. Successful exploitation can lead to security compromises and potential data loss. It is highly recommended that WordPress users update to the latest version of the tagDiv Composer plugin to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.