CVE-2025-23640
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-23640 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Rename Author Slug plugin version 1.2.0 and below. An attacker can exploit this issue to perform Stored XSS (Cross-Site Scripting) attacks on unsuspecting users. The flaw lies in the way the plugin handles author slug renaming, allowing an attacker to inject malicious scripts that persist even after the page is refreshed. Successful exploitation could lead to data theft or unintended actions carried out on behalf of the victim. Users are recommended to update to the latest plugin version to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.