Cross-Site Request Forgery Vulnerability in yonisink Custom Post Type Images
CVE-2025-58255

9.6CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2025

What is CVE-2025-58255?

A Cross-Site Request Forgery (CSRF) vulnerability in the yonisink Custom Post Type Images plugin allows malicious actors to inject code via unauthorized requests. This flaw, which is present in Custom Post Type Images versions up to and including 0.5, can lead to potential exploitation if the user is tricked into making a request while authenticated. Website administrators are encouraged to update their plugins and implement security measures to safeguard against such attacks.

Affected Version(s)

Custom Post Type Images <= 0.5

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.