Cross-Site Request Forgery in WP Discord Post Plus by WordPress
CVE-2025-49896
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2025
What is CVE-2025-49896?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Discord Post Plus plugin for WordPress. This vulnerability allows an unauthorized attacker to perform actions on behalf of a user without their consent. The affected versions include all prior to 1.0.2, potentially compromising users' interaction with Discord through the plugin. It is essential for users of WP Discord Post Plus to update to the latest version to mitigate this risk and protect their sites from potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Discord Post Plus – Supports Unlimited Channels <= 1.0.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved