CSRF Vulnerability in WP-Database-Optimizer-Tools by WordPress
CVE-2025-53219

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
14 August 2025

What is CVE-2025-53219?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP-Database-Optimizer-Tools plugin, potentially allowing attackers to execute unauthorized actions on behalf of authenticated users. This vulnerability impacts versions from n/a to 0.2, leading to significant security risks for users who have not updated their plugins. It is essential for users to apply available patches and follow best practices to mitigate the risks associated with this vulnerability.

Affected Version(s)

WP-Database-Optimizer-Tools <= 0.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Skalucy (Patchstack Alliance)
.
CVE-2025-53219 : CSRF Vulnerability in WP-Database-Optimizer-Tools by WordPress