Cross-Site Request Forgery Vulnerability in Visit Counter Plugin for WordPress
CVE-2025-12452
What is CVE-2025-12452?
The Visit Counter plugin for WordPress is exposed to a Cross-Site Request Forgery vulnerability in version 1.0 due to inadequate nonce validation on the widgets.php page. This oversight allows unauthenticated attackers to manipulate the settings of the plugin by tricking site administrators into executing forged requests, such as clicking on deceptive links. Such exploits can lead to unauthorized changes and potentially allow for the injection of malicious scripts, posing significant risks to the integrity of WordPress sites utilizing this plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Visit Counter 1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved