Cross-Site Request Forgery in Mailing Group Listserv by Yamna Khawaja
CVE-2025-50036

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 June 2025

What is CVE-2025-50036?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Mailing Group Listserv plugin developed by Yamna Khawaja. This security issue allows attackers to execute unauthorized actions on behalf of users without their consent. The vulnerability affects the Mailing Group Listserv plugin from its initial release up to version 3.0.5, posing a risk to any site that utilizes this plugin. Proper security measures should be enacted to mitigate the potential for unauthorized access and control.

Affected Version(s)

Mailing Group Listserv <= 3.0.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.