CVE-2025-23797

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23797 is a Cross-Site Request Forgery (CSRF) vulnerability impacting the WP Options Editor plugin. This issue enables privilege escalation, allowing unauthorized users to manipulate settings with higher-level permissions. The WP Options Editor, affected from an undisclosed version up to 1.1, is put at risk due to this security flaw.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share