Cross-Site Request Forgery Vulnerability in Scriptonite Simple User Profile Plugin
CVE-2025-25140

7.1HIGH

Key Information:

Vendor
Scriptonite
Status
Simple User Profile
Vendor
CVE Published:
7 February 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability in the Scriptonite Simple User Profile plugin can allow attackers to manipulate user sessions and potentially execute Stored XSS attacks. This vulnerability affects all versions of the plugin up to and including 1.9, posing risks to sites using this plugin as it can be exploited without direct user interaction. Mitigating this vulnerability is critical for maintaining the security of WordPress installations utilizing this plugin.

Affected Version(s)

Simple User Profile <= 1.9

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdi Pranata (Patchstack Alliance)
.