Cross-Site Request Forgery in Geotagged Media Plugin by WordPress
CVE-2025-23558
7.1HIGH
What is CVE-2025-23558?
A Cross-Site Request Forgery (CSRF) vulnerability in the Geotagged Media plugin allows attackers to exploit the functionality of the plugin, potentially leading to Stored Cross-Site Scripting (XSS) attacks. This vulnerability affects versions n/a through 0.3.0, enabling unauthorized commands to be executed in the context of the authenticated user, which can compromise the security of the affected WordPress site.
Affected Version(s)
Geotagged Media <= 0.3.0