Cross-Site Request Forgery Vulnerability in Zegen Core Plugin for WordPress
CVE-2025-11087

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 November 2025

What is CVE-2025-11087?

The Zegen Core plugin for WordPress is exposed to a Cross-Site Request Forgery vulnerability that allows unauthorized file uploads due to insufficient nonce validation and file type checks in the '/custom-font-code/custom-fonts-uploads.php' file. This vulnerability can be exploited by attackers to upload arbitrary files to the server, potentially facilitating remote code execution, especially if they can deceive a site administrator into triggering the upload through a malicious link.

Affected Version(s)

Zegen Core * <= 2.0.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

István Márton
.
CVE-2025-11087 : Cross-Site Request Forgery Vulnerability in Zegen Core Plugin for WordPress