CVE-2025-30521
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Mar 24, 2025
Updated: Mar 27, 2025
CWE ID 352
Summary
CVE-2025-30521 is a Cross-Site Request Forgery (CSRF) vulnerability affecting GP Back To Top, a plugin used to add a "Back to Top" button to websites. This issue, which impacts versions from n/a through 3.0, enables malicious actors to perform unintended actions on the affected website on behalf of the current user. CSRF attacks trick users into unknowingly making requests to a website, potentially resulting in data theft, account takeover, or other unintended consequences. It is crucial to update GP Back To Top to a patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress