CVE-2025-39601

CVSS 3.1 Score 9.6 of 10 (high)

Details

Published Apr 16, 2025
CWE ID 352

Summary

CVE-2025-39601 is a Cross-Site Request Forgery (CSRF) vulnerability affecting WPFactory's Custom CSS, JS & PHP. This issue permits attackers to include remote code, posing a significant security risk. The vulnerability can be exploited in versions of Custom CSS, JS & PHP from n/a through 2.4.1. It is crucial for users to update to a secure version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share