CVE-2025-28941
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-28941 represents a Cross-Site Request Forgery (CSRF) vulnerability in the Spam Byebye application, version n/a through 2.2.4. This issue allows an attacker to submit malicious requests on behalf of a user who is currently authenticated on the application's website. The CSRF vulnerability can potentially lead to unintended user actions, such as account modifications or data exfiltration. Attackers can exploit this flaw by tricking users into visiting a malicious website or clicking on a specially crafted link, leading to unauthorized actions being performed in the affected application. Users are advised to update their Spam Byebye installations to the latest version to mitigate the risk of this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress