CVE-2025-23902
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-23902 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Error Notification component of Taras Dashkevych's software. This issue enables attackers to execute malicious actions on a victim's account by tricking them into visiting a specially crafted URL. The Error Notification component, which is used from an unknown version up to 0.2.7, is the affected part of the software. Successful exploitation could result in unintended modifications or data loss for the vulnerable system or account. Users are urged to upgrade to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress