Cross-Site Request Forgery Vulnerability in Resource Library for Logged In Users Plugin by WordPress
CVE-2025-14354
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 December 2025
What is CVE-2025-14354?
The Resource Library for Logged In Users plugin for WordPress is susceptible to Cross-Site Request Forgery due to inadequate nonce validation in its administrative functions. This deficiency allows potential attackers to exploit this vulnerability by tricking site administrators into executing unauthorized actions, such as the unauthorized creation, modification, or deletion of resources and categories. As a result, it poses a significant security risk for WordPress users.
Affected Version(s)
Resource Library for Logged In Users * <= 1.4