Cross-Site Request Forgery Vulnerability in Audio Comments Plugin for WordPress
CVE-2025-4189
What is CVE-2025-4189?
The Audio Comments Plugin for WordPress presents a Cross-Site Request Forgery risk in all versions up to and including 1.0.4. The vulnerability stems from inadequate nonce validation on the 'audio-comments/audior-settings.php' page. This flaw could allow attackers to exploit the system by tricking a site administrator into clicking a malicious link, potentially leading to unauthorized changes in plugin settings and the injection of harmful scripts. It is crucial for users to apply updates and implement security measures to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Audio Comments Plugin * <= 1.0.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved