Cross-Site Request Forgery in URL-Preview-Box by Mraliende
CVE-2025-25104
7.1HIGH
What is CVE-2025-25104?
A Cross-Site Request Forgery (CSRF) vulnerability in the URL-Preview-Box plugin by Mraliende allows an attacker to trick a user into executing unwanted actions on a web application. This vulnerability affects versions of URL-Preview-Box up to 1.20, potentially compromising user sessions and enabling unauthorized actions.
Affected Version(s)
URL-Preview-Box 0 <= 1.20