Cross-Site Request Forgery Vulnerability in System Dashboard Plugin for WordPress
CVE-2025-10377
4.3MEDIUM
What is CVE-2025-10377?
The System Dashboard plugin for WordPress is susceptible to Cross-Site Request Forgery due to inadequate nonce validation in the sd_toggle_logs() function. This vulnerability allows unauthenticated attackers to manipulate critical logging settingsāincluding Page Access Logs, Error Logs, and Email Delivery Logsāby tricking site administrators into performing unauthorized actions, such as clicking compromised links. This raises significant security concerns for site management and data integrity, particularly if the plugin is not updated to version 2.8.21 or later.
Affected Version(s)
System Dashboard * <= 2.8.20