CVE-2025-3866
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 79
Summary
CVE-2025-3866 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Add Google +1 (Plus one) social share Button plugin for WordPress. Versions up to and including 1.0.0 are vulnerable. This issue stems from insufficient or faulty nonce validation on the google-plus-one-share-button page. Consequently, unauthenticated attackers can manipulate plugin settings and introduce malicious web scripts, provided they successfully trick site administrators into performing a specific action like clicking a malicious link.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.