Cross-Site Request Forgery Vulnerability in ThemeFarmer Ultimate Subscribe Plugin
CVE-2025-23806
7.1HIGH
What is CVE-2025-23806?
A Cross-Site Request Forgery (CSRF) vulnerability in the ThemeFarmer Ultimate Subscribe plugin allows attackers to execute Reflected Cross-Site Scripting (XSS) attacks. This flaw enables unauthorized actions to be performed on behalf of a user without their consent. The vulnerability impacts all versions of the plugin from n/a through 1.3, exposing sites to potential malicious exploits and highlighting the need for immediate updates and security practices.
Affected Version(s)
Ultimate Subscribe <= 1.3