CVE-2025-2111

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 19, 2025
Updated: Apr 21, 2025
CWE ID 352

Summary

CVE-2025-2111 is a Cross-Site Request Forgery vulnerability affecting the Insert Headers And Footers plugin for WordPress. Versions up to 3.1.1 are vulnerable due to insufficient nonce validation on the 'custom_plugin_set_option' function. An attacker can exploit this by tricking a site administrator into performing an action, such as clicking on a malicious link, allowing the attacker to update arbitrary options on the WordPress site. This includes the default role for registration, which can be changed to administrator, enabling user registration for attackers and granting them administrative access to the vulnerable site. Exploitation requires the 'WPBRIGADE_SDK__DEV_MODE' constant to be set to 'true'.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share