Cross-Site Request Forgery Vulnerability in WordPress Signature by Abinav Thakuri
CVE-2025-22704
5.4MEDIUM
Key Information:
- Vendor
- Abinav Thakuri
- Status
- WordPress Signature
- Vendor
- CVE Published:
- 3 February 2025
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Signature plugin developed by Abinav Thakuri. This security flaw allows unauthorized actions to be performed on behalf of authenticated users without their consent. The vulnerability affects all versions of WordPress Signature up to and including 0.1, posing significant risks to user data and site integrity.
Affected Version(s)
WordPress Signature <= 0.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abdi Pranata (Patchstack Alliance)