Cross-Site Request Forgery Vulnerability in Bhzad WP jQuery Persian Datepicker Plugin
CVE-2025-28861
6.1MEDIUM
What is CVE-2025-28861?
A Cross-Site Request Forgery (CSRF) vulnerability in the Bhzad WP jQuery Persian Datepicker plugin allows attackers to perform actions on behalf of authenticated users without their consent. This flaw can lead to Stored Cross-Site Scripting (XSS) attacks, which can compromise user data and security. The issue affects versions from n/a through 0.1.0, emphasizing the need for website administrators to promptly update and secure their WordPress installations.
Affected Version(s)
WP jQuery Persian Datepicker <= 0.1.0