CVE-2025-23510

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23510 is a newly disclosed vulnerability that affects the WordPress Logging Service, specifically versions from n/a to 1.5.4. This issue combines Cross-Site Request Forgery (CSRF) and Stored XSS (Cross-Site Scripting) threats. An attacker could exploit this CSRF vulnerability to inject malicious scripts into a user's web session, potentially leading to unauthorized actions and data theft. Since the vulnerability involves Stored XSS, the injected scripts could persist even after the user logs out, posing a significant risk to the affected users.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share