CVE-2025-22297
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-22297 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the AI WP Writer plugin, from an unknown version up to 3.8.4.4. This issue enables an attacker to manipulate a user's browser into performing unintended actions, such as account takeover or data modification, on the affected website without their knowledge. The attacker can achieve this by tricking the user into visiting a malicious website or clicking on a specially crafted link, leading to potential security risks for the user and the affected website. It is crucial for users of AI WP Writer to update their plugin to the latest version, implementing CSRF protection measures and staying informed of security updates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.