Cross-Site Request Forgery Vulnerability in Scriptonite Simple User Profile Plugin
CVE-2025-25140
7.1HIGH
What is CVE-2025-25140?
A Cross-Site Request Forgery (CSRF) vulnerability in the Scriptonite Simple User Profile plugin can allow attackers to manipulate user sessions and potentially execute Stored XSS attacks. This vulnerability affects all versions of the plugin up to and including 1.9, posing risks to sites using this plugin as it can be exploited without direct user interaction. Mitigating this vulnerability is critical for maintaining the security of WordPress installations utilizing this plugin.
Affected Version(s)
Simple User Profile <= 1.9