Cross-Site Request Forgery in ProfitShare Plugin by WordPress
CVE-2025-31906
7.1HIGH
What is CVE-2025-31906?
A Cross-Site Request Forgery (CSRF) vulnerability in the WP Profitshare plugin for WordPress allows attackers to execute unauthorized actions on behalf of a user. This security flaw can potentially lead to Stored Cross-Site Scripting (XSS), where malicious scripts can be injected unless the user takes appropriate actions. The vulnerability affects all versions upto 1.4.9 of the WP Profitshare plugin, making it crucial for administrators to apply security patches and updates as recommended.
Affected Version(s)
WP Profitshare <= 1.4.9