Cross-Site Request Forgery Vulnerability in Nokri Theme by PatchStack
CVE-2025-58259

7.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
22 September 2025

What is CVE-2025-58259?

A Cross-Site Request Forgery (CSRF) vulnerability exists in versions of the Nokri Theme up to 1.6.4. This security issue can potentially allow attackers to perform unauthorized actions on behalf of authenticated users without their consent. Ensuring that users’ sessions are protected from CSRF attacks is essential to maintain the integrity and security of web applications.

Affected Version(s)

Nokri 0 <= 1.6.4

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)
.