Cross-Site Request Forgery Vulnerability in Lucky Draw Contests Plugin for WordPress
CVE-2025-14462
4.3MEDIUM
What is CVE-2025-14462?
The Lucky Draw Contests plugin for WordPress contains a vulnerability due to inadequate nonce validation in the settings file. This flaw allows unauthenticated attackers to exploit the plugin by tricking an administrator into executing a forged request, thereby compromising authentication and potentially allowing unauthorized changes to critical plugin settings.
Affected Version(s)
Lucky Draw Contests * <= 4.2