CVE-2025-39601
CVSS 3.1 Score 9.6 of 10 (high)
Details
Published Apr 16, 2025
CWE ID 352
Summary
CVE-2025-39601 is a Cross-Site Request Forgery (CSRF) vulnerability affecting WPFactory's Custom CSS, JS & PHP. This issue permits attackers to include remote code, posing a significant security risk. The vulnerability can be exploited in versions of Custom CSS, JS & PHP from n/a through 2.4.1. It is crucial for users to update to a secure version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.