Cross-Site Request Forgery Vulnerability in Multi Item Responsive Slider Plugin for WordPress
CVE-2025-11992
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 October 2025
What is CVE-2025-11992?
The Multi Item Responsive Slider plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit missing nonce validation on the 'mioptions.php' page. By tricking a site administrator into performing actions through crafted links, attackers can potentially alter settings and inject malicious scripts, compromising site integrity. It is crucial for users of this plugin, particularly those running versions up to and including 1.0, to implement necessary updates and security measures.
Affected Version(s)
Multi Item Responsive Slider * <= 1.0