CVE-2025-31474
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-31474 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the WP Database Optimizer plugin. This issue permits unauthorized users to submit malicious requests on behalf of other users who have previously accessed the vulnerable page. The WP Database Optimizer plugin, from all versions up to and including 1.2.1.3, is reportedly affected by this vulnerability. Successful exploitation could lead to various unwanted actions, such as data modification or unauthorized account access. Users are strongly advised to update the plugin to the latest version or consider disabling it until a patch is released.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.