CSRF Vulnerability in Hasina77 Wp Easy Allopass Plugin
CVE-2025-49435
4.3MEDIUM
What is CVE-2025-49435?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Hasina77 Wp Easy Allopass plugin that allows attackers to trick users into performing unwanted actions. This can lead to unauthorized changes or information disclosure when users are manipulated into interacting with the application unknowingly. The affected versions include all releases from n/a to 4.1.1.
Affected Version(s)
Wp Easy Allopass <= 4.1.1