CVE-2025-1762
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Mar 28, 2025
Updated: Apr 17, 2025
CWE ID 352
Summary
CVE-2025-1762 is a vulnerability affecting the Event Tickets with Ticket Scanner WordPress plugin before version 2.5.4. This issue exposes a Cross-Site Request Forgery (CSRF) weakness, permitting attackers to manipulate admin settings unauthorizedly. An admin user's actions, such as updating plugin settings, can be altered via a maliciously crafted request, posing a potential security risk to the affected site. It is strongly advised to update the plugin to its latest version as soon as possible to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.