Cross-Site Request Forgery Vulnerability in Simple Page Access Restriction Plugin by WordPress
CVE-2025-5142
What is CVE-2025-5142?
The Simple Page Access Restriction plugin for WordPress is susceptible to a Cross-Site Request Forgery attack due to improper nonce validation and capability checks in its settings.php script. As a result, unauthorized users could potentially manipulate access settings for all post types or taxonomies, altering the visibility of new postings regardless of the intended privacy settings. Additionally, this vulnerability may lead to the unintended deletion of plugin data upon removal, as well as the risk of URL redirection attacks if an administrator is tricked into interacting with a compromised link.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Simple Page Access Restriction * <= 1.0.31
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved