Cross-Site Request Forgery in Bread & Butter Plugin for WordPress
CVE-2025-12189

4.3MEDIUM

What is CVE-2025-12189?

The Bread & Butter plugin for WordPress is susceptible to a Cross-Site Request Forgery vulnerability due to insufficient nonce validation in its uploadImage() function. An unauthenticated attacker could exploit this weakness to upload arbitrary files, potentially leading to remote code execution. If an administrator is tricked into clicking a malicious link, the attacker can execute harmful actions on the site. It is crucial for users of the plugin to apply security measures and updates to mitigate this risk.

Affected Version(s)

Bread & Butter: Gate content & Improve lead conversion in 60 seconds * <= 7.10.1321

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ryan Kozak
.
CVE-2025-12189 : Cross-Site Request Forgery in Bread & Butter Plugin for WordPress