Cross-Site Request Forgery Risk in PixelYourSite for WordPress
CVE-2025-10588
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 October 2025
What is CVE-2025-10588?
The PixelYourSite plugin for WordPress features a security flaw that allows attackers to exploit Cross-Site Request Forgery (CSRF) vulnerabilities. This issue stems from inadequate nonce validation in the adminEnableGdprAjax() function, which facilitates unauthorized changes to GDPR settings. Attackers can potentially manipulate these settings if they successfully deceive a site administrator into triggering a malicious action, such as clicking a crafted link. It is critical for administrators to ensure plugin updates are applied to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PixelYourSite β Your smart PIXEL (TAG) & API Manager * <= 11.1.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved