Cross-Site Request Forgery Vulnerability in Infigo Software IS-theme-companion
CVE-2025-53277

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 June 2025

What is CVE-2025-53277?

The IS-theme-companion by Infigo Software is affected by a Cross-Site Request Forgery (CSRF) vulnerability, which enables attackers to trigger actions on behalf of authenticated users without their consent. This weakness can lead to object injection, posing significant risks to the security of affected installations. It is crucial for users to apply any available patches or updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

IS-theme-companion <= 1.57

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Tran Tuan Dung (domiee13) (Patchstack Alliance)
.
CVE-2025-53277 : Cross-Site Request Forgery Vulnerability in Infigo Software IS-theme-companion