Cross-Site Request Forgery Vulnerability in WordPress Signature by Abinav Thakuri
CVE-2025-22704

5.4MEDIUM

Key Information:

Vendor
Abinav Thakuri
Status
WordPress Signature
Vendor
CVE Published:
3 February 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Signature plugin developed by Abinav Thakuri. This security flaw allows unauthorized actions to be performed on behalf of authenticated users without their consent. The vulnerability affects all versions of WordPress Signature up to and including 0.1, posing significant risks to user data and site integrity.

Affected Version(s)

WordPress Signature <= 0.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdi Pranata (Patchstack Alliance)
.