CVE-2025-1762

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 28, 2025
Updated: Apr 17, 2025
CWE ID 352

Summary

CVE-2025-1762 is a vulnerability affecting the Event Tickets with Ticket Scanner WordPress plugin before version 2.5.4. This issue exposes a Cross-Site Request Forgery (CSRF) weakness, permitting attackers to manipulate admin settings unauthorizedly. An admin user's actions, such as updating plugin settings, can be altered via a maliciously crafted request, posing a potential security risk to the affected site. It is strongly advised to update the plugin to its latest version as soon as possible to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share