Cross-Site Request Forgery in WP Discord Post Plus by WordPress
CVE-2025-49896

4.3MEDIUM

What is CVE-2025-49896?

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Discord Post Plus plugin for WordPress. This vulnerability allows an unauthorized attacker to perform actions on behalf of a user without their consent. The affected versions include all prior to 1.0.2, potentially compromising users' interaction with Discord through the plugin. It is essential for users of WP Discord Post Plus to update to the latest version to mitigate this risk and protect their sites from potential exploits.

Affected Version(s)

WP Discord Post Plus &#8211; Supports Unlimited Channels <= 1.0.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bao - BlueRock (Patchstack Alliance)
.