Cross-Site Request Forgery in WP Discord Post Plus by WordPress
CVE-2025-49896
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2025
What is CVE-2025-49896?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Discord Post Plus plugin for WordPress. This vulnerability allows an unauthorized attacker to perform actions on behalf of a user without their consent. The affected versions include all prior to 1.0.2, potentially compromising users' interaction with Discord through the plugin. It is essential for users of WP Discord Post Plus to update to the latest version to mitigate this risk and protect their sites from potential exploits.
Affected Version(s)
WP Discord Post Plus – Supports Unlimited Channels <= 1.0.2