CVE-2025-2163

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 15, 2025
Updated: Mar 28, 2025
CWE ID 416

Summary

CVE-2025-2163 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Zoorum Comments plugin for WordPress. Versions up to 0.9 are impacted by this issue. The vulnerability stems from missing or incorrect nonce validation on the zoorum_set_options() function. As a result, unauthenticated attackers can manipulate plugin settings and inject malicious web scripts by tricking site administrators into executing a malicious request. This poses a significant risk for websites using the affected plugin, as it allows attackers to gain unauthorized control and potentially compromise the entire site.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share