Cross-Site Request Forgery in Video Merchant Plugin for WordPress
CVE-2025-14390
8.8HIGH
What is CVE-2025-14390?
The Video Merchant plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit Cross-Site Request Forgery due to improper nonce validation in the video_merchant_add_video_file() function. This flaw enables attackers to upload arbitrary files via forged requests, potentially leading to remote code execution if they can manipulate a site administrator into executing an action on the compromised site.
Affected Version(s)
Video Merchant * <= 5.0.4