CVE-2025-39416
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-39416 is a newly disclosed vulnerability affecting the Ichi translit it! software. This issue combines a Cross-Site Request Forgery (CSRF) weakness with the potential for Stored Cross-Site Scripting (XSS). The CSRF vulnerability permits attackers to hijack user sessions and execute unintended actions on their behalf. Simultaneously, the Stored XSS component allows adversaries to inject malicious scripts into web pages, potentially stealing sensitive information or taking control of users' devices. The vulnerability spans from versions n/a to 1.6 of the translit it! software.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress