CVE-2025-30804

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 27, 2025
CWE ID 352

Summary

CVE-2025-30804 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the wpShopGermany IT-RECHT KANZLEI plugin from version n/a to 2.0. This issue enables attackers to trick users into making unintended actions on the affected website, such as changing account settings or initiating transactions, by forging malicious requests. The vulnerability poses a significant risk to users who visit malicious websites, as they could unwittingly execute unwanted actions on the targeted site. It is essential for users to update their wpShopGermany IT-RECHT KANZLEI plugin to a patched version to mitigate this CSRF vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share