CVE-2025-31769
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-31769 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the NiteoThemes CLP – Custom Login Page version 1.5.5 and below. Malicious actors can exploit this issue to perform unauthorized actions on behalf of users who have previously visited the attacker's website. This vulnerability allows the attacker to submit malicious requests to the login page, potentially gaining access to user accounts or administrative functions, posing a significant security risk. It is essential to update the CLP plugin to the latest version to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.