CVE-2025-30546
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-30546 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the boroV Cackle software. This issue permits malicious actors to submit unintended commands or modifications to the affected system on behalf of a user, due to insufficient validation of user input. The vulnerability can be exploited if a user visits a specially crafted website while logged in to Cackle, from versions 4.33 and prior. Successful exploitation could result in unauthorized actions, including account takeover or data modifications. Users are advised to upgrade to the latest version of Cackle and apply additional security measures to mitigate the risk of CSRF attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress