Cross-Site Request Forgery Vulnerability in Popover Windows Plugin for WordPress
CVE-2025-14394
4.3MEDIUM
What is CVE-2025-14394?
The Popover Windows plugin for WordPress suffers from a vulnerability that allows unauthenticated attackers to exploit Cross-Site Request Forgery (CSRF) due to missing nonce validation in versions up to and including 1.2. This flaw enables malicious actors to alter the plugin's settings by tricking a site administrator into initiating a fraudulent request, such as clicking a specially crafted link. Keeping the plugin updated and implementing proper nonce validation is crucial to safeguard against this type of attack.
Affected Version(s)
Popover Windows * <= 1.2