CVE-2025-2111
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-2111 is a Cross-Site Request Forgery vulnerability affecting the Insert Headers And Footers plugin for WordPress. Versions up to 3.1.1 are vulnerable due to insufficient nonce validation on the 'custom_plugin_set_option' function. An attacker can exploit this by tricking a site administrator into performing an action, such as clicking on a malicious link, allowing the attacker to update arbitrary options on the WordPress site. This includes the default role for registration, which can be changed to administrator, enabling user registration for attackers and granting them administrative access to the vulnerable site. Exploitation requires the 'WPBRIGADE_SDK__DEV_MODE' constant to be set to 'true'.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.