Cross-Site Request Forgery in Mindstien Technologies Recent Posts Plugin
CVE-2025-49354
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 December 2025
What is CVE-2025-49354?
A Cross-Site Request Forgery (CSRF) vulnerability in the Recent Posts From Each Category plugin by Mindstien Technologies allows attackers to execute unauthorized actions on behalf of users. This can lead to the execution of stored cross-site scripting (XSS) attacks, potentially allowing malicious payloads to be delivered to unsuspecting users. The issue impacts all versions of the plugin up to 1.4, putting WordPress sites leveraging this plugin at significant risk.
Affected Version(s)
Recent Posts From Each Category 0 <= 1.4