CSRF Vulnerability in RSTheme Ultimate Coming Soon & Maintenance Plugin
CVE-2025-24546

5.4MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
24 January 2025

Summary

The RSTheme Ultimate Coming Soon & Maintenance plugin is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This flaw permits attackers to exploit the web application by tricking users into executing unwanted actions without their consent, potentially compromising the integrity of the plugin and impacting the security of the website it is deployed on. The affected versions range from n/a to 1.0.9, necessitating prompt updates and security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

Ultimate Coming Soon & Maintenance <= 1.0.9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marek Mikita (Patchstack Alliance)
.