CVE-2025-30521

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 24, 2025
Updated: Mar 27, 2025
CWE ID 352

Summary

CVE-2025-30521 is a Cross-Site Request Forgery (CSRF) vulnerability affecting GP Back To Top, a plugin used to add a "Back to Top" button to websites. This issue, which impacts versions from n/a through 3.0, enables malicious actors to perform unintended actions on the affected website on behalf of the current user. CSRF attacks trick users into unknowingly making requests to a website, potentially resulting in data theft, account takeover, or other unintended consequences. It is crucial to update GP Back To Top to a patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share