CVE-2025-23446

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 3, 2025
CWE ID 352

Summary

CVE-2025-23446 is a newly disclosed vulnerability that impacts the WP SpaceContent plugin, affecting versions from n/a to 0.4.5. This issue combines two serious threats: Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS). An attacker can exploit the CSRF vulnerability to execute malicious actions on behalf of a user, while the Stored XSS component allows the injection of malicious scripts into web pages viewed by other users. These combined threats pose a significant risk to websites using the affected WP SpaceContent plugin. It is recommended that users upgrade to the latest version of the plugin as soon as possible to mitigate these vulnerabilities.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share