CVE-2025-28887
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Mar 11, 2025
CWE ID 352
Summary
CVE-2025-28887 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Plugins Last Updated Column in Fastmover. This issue, present in versions from n/a through 0.1.3, allows malicious actors to manipulate user actions by submitting specially crafted requests to the affected system on behalf of the victim, potentially leading to unauthorized plugin updates or other unwanted actions. Users are advised to upgrade to the latest version of the Plugins Last Updated Column to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress