Cross-Site Request Forgery Vulnerability in Latest Tabs Plugin for WordPress
CVE-2025-14999
4.3MEDIUM
What is CVE-2025-14999?
The Latest Tabs plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF) due to inadequate nonce validation in its settings update handler found in admin-page.php. This flaw permits unauthorized attackers to alter plugin settings by inducing a site administrator to unknowingly click on a malicious link, leading to potential exploitation of the WordPress site.
Affected Version(s)
Latest Tabs 0 <= 1.5