CSRF Vulnerability in RSTheme Ultimate Coming Soon & Maintenance Plugin
CVE-2025-24546
5.4MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 24 January 2025
Summary
The RSTheme Ultimate Coming Soon & Maintenance plugin is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This flaw permits attackers to exploit the web application by tricking users into executing unwanted actions without their consent, potentially compromising the integrity of the plugin and impacting the security of the website it is deployed on. The affected versions range from n/a to 1.0.9, necessitating prompt updates and security measures to mitigate the risks associated with this vulnerability.
Affected Version(s)
Ultimate Coming Soon & Maintenance <= 1.0.9
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marek Mikita (Patchstack Alliance)