CVE-2025-2163
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2025-2163 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Zoorum Comments plugin for WordPress. Versions up to 0.9 are impacted by this issue. The vulnerability stems from missing or incorrect nonce validation on the zoorum_set_options() function. As a result, unauthenticated attackers can manipulate plugin settings and inject malicious web scripts by tricking site administrators into executing a malicious request. This poses a significant risk for websites using the affected plugin, as it allows attackers to gain unauthorized control and potentially compromise the entire site.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX