Cross-Site Request Forgery Vulnerability in Reuters Direct Plugin for WordPress
CVE-2025-12578
4.3MEDIUM
What is CVE-2025-12578?
The Reuters Direct plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) issue. The vulnerability arises from inadequate nonce validation on the 'class-reuters-direct-settings.php' page, allowing unauthenticated attackers to exploit this flaw. By deceiving a site administrator into executing a malicious request, attackers can manipulate the plugin’s settings without authorization, posing a security risk to affected WordPress installations.
Affected Version(s)
Reuters Direct * <= 3.0.0