CVE-2025-23804

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23804 is a newly discovered vulnerability affecting the WP Service Payment Form With Authorize.net plugin. The issue involves a Cross-Site Request Forgery (CSRF) weakness that also permits Reflected Cross-Site Scripting (XSS). This vulnerability can exploit users of this plugin, which is used for processing payments through Authorize.net, from any version up to 2.6.0. Attackers can manipulate user sessions to inject malicious scripts and potentially steal sensitive data. Users are strongly advised to update to the latest version of the plugin to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share