CVE-2025-24699
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-24699 is a newly disclosed vulnerability affecting the WP Coder plugin for WordPress. This issue combines a Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) vulnerability in the plugin. An attacker can exploit the CSRF flaw to force a user into performing unwanted actions on the WP Coder dashboard, while the XSS vulnerability enables the attacker to inject malicious scripts into the affected website. This vulnerability poses a serious risk to websites using the WP Coder plugin from versions n/a through 3.6. It is crucial for users to update to the latest version of WP Coder or consider alternative plugins to mitigate this security threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.