CVE-2025-23715

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23715 is a Cross-Site Request Forgery (CSRF) vulnerability identified in the RaymondDesign Post & Page Notes plugin. This issue permits attackers to execute Stored Cross-Site Scripting (XSS) attacks on unsuspecting users. The vulnerability affects versions of Post & Page Notes from n/a through 0.1.1, making it essential for users to update their plugins to mitigate this risk. By exploiting this CSRF flaw, attackers can inject malicious scripts into a user's web session, potentially leading to data theft or other malicious activities.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share