CVE-2025-30804
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-30804 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the wpShopGermany IT-RECHT KANZLEI plugin from version n/a to 2.0. This issue enables attackers to trick users into making unintended actions on the affected website, such as changing account settings or initiating transactions, by forging malicious requests. The vulnerability poses a significant risk to users who visit malicious websites, as they could unwittingly execute unwanted actions on the targeted site. It is essential for users to update their wpShopGermany IT-RECHT KANZLEI plugin to a patched version to mitigate this CSRF vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress