Cross-Site Request Forgery in CompleteWebResources Social Share Buttons by WordPress
CVE-2025-26580
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 February 2025
What is CVE-2025-26580?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the CompleteWebResources Page/Post Specific Social Share Buttons plugin. This vulnerability allows an attacker to execute unauthorized actions on behalf of an authenticated user, potentially leading to Stored Cross-Site Scripting (XSS) attacks. This affects versions from n/a through 2.1, posing significant risks to user data and site integrity. It is crucial for users to patch their installations and implement security best practices to mitigate these threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Page/Post Specific Social Share Buttons <= 2.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved