CVE-2025-32655
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-32655 is a newly discovered vulnerability affecting the DevriX Restrict User Registration plugin. This issue combines a Cross-Site Request Forgery (CSRF) weakness with Stored Cross-Site Scripting (XSS), allowing an attacker to inject malicious scripts into a user's browser. The CSRF vulnerability can be exploited to perform unauthorized actions, such as account takeovers, while the Stored XSS can result in persistent data compromise. This vulnerability impacts all versions of the plugin from n/a through 1.0.1. It is essential for users to apply the available patch or upgrade to a version that addresses this issue to secure their WordPress installations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.