CVE-2025-31474

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 28, 2025
CWE ID 352

Summary

CVE-2025-31474 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the WP Database Optimizer plugin. This issue permits unauthorized users to submit malicious requests on behalf of other users who have previously accessed the vulnerable page. The WP Database Optimizer plugin, from all versions up to and including 1.2.1.3, is reportedly affected by this vulnerability. Successful exploitation could lead to various unwanted actions, such as data modification or unauthorized account access. Users are strongly advised to update the plugin to the latest version or consider disabling it until a patch is released.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share