Cross-Site Request Forgery Vulnerability in Simple Page Access Restriction Plugin by WordPress
CVE-2025-5142
6.5MEDIUM
What is CVE-2025-5142?
The Simple Page Access Restriction plugin for WordPress is susceptible to a Cross-Site Request Forgery attack due to improper nonce validation and capability checks in its settings.php script. As a result, unauthorized users could potentially manipulate access settings for all post types or taxonomies, altering the visibility of new postings regardless of the intended privacy settings. Additionally, this vulnerability may lead to the unintended deletion of plugin data upon removal, as well as the risk of URL redirection attacks if an administrator is tricked into interacting with a compromised link.
Affected Version(s)
Simple Page Access Restriction * <= 1.0.31