Cross-Site Request Forgery vulnerability in WP Spell Check by WordPress
CVE-2025-25111
5.4MEDIUM
What is CVE-2025-25111?
The WP Spell Check plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability, allowing attackers to perform unauthorized actions on behalf of users. This security flaw impacts versions from n/a through 9.21, potentially exposing sites to unwanted changes and manipulations without users' consent. It is crucial for site administrators to patch the vulnerability to safeguard their installations.
Affected Version(s)
WP Spell Check <= 9.21