Cross-Site Request Forgery Vulnerability in Scriptonite Simple User Profile Plugin
CVE-2025-25140
7.1HIGH
Key Information:
- Vendor
- Scriptonite
- Status
- Simple User Profile
- Vendor
- CVE Published:
- 7 February 2025
Summary
A Cross-Site Request Forgery (CSRF) vulnerability in the Scriptonite Simple User Profile plugin can allow attackers to manipulate user sessions and potentially execute Stored XSS attacks. This vulnerability affects all versions of the plugin up to and including 1.9, posing risks to sites using this plugin as it can be exploited without direct user interaction. Mitigating this vulnerability is critical for maintaining the security of WordPress installations utilizing this plugin.
Affected Version(s)
Simple User Profile <= 1.9
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abdi Pranata (Patchstack Alliance)