CVE-2025-39548
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-39548 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Right Click Disable OR Ban plugin for WordPress. The flaw, present in versions 1.1.17 and earlier, allows an attacker to execute Stored Cross-Site Scripting (XSS) attacks on unsuspecting users. This can lead to the theft of user data or session hijacking. An attacker can exploit this vulnerability by crafting a malicious link that, when clicked, triggers a malicious request from the victim's browser, potentially leading to the execution of malicious scripts. Users of the Right Click Disable OR Ban plugin are advised to update to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.