CVE-2025-3870
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 79
Summary
CVE-2025-3870 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the 1 Decembrie 1918 plugin for WordPress. Versions up to and including 1.dec.2012 are susceptible to this issue. The root cause is the lack of proper nonce validation on the 1-decembrie-1918/1-decembrie-1918.php page. As a result, unauthenticated attackers can manipulate site settings and inject malicious web scripts by deceiving administrators into executing a malicious request via a link click.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.