Cross-Site Request Forgery in WP Attractive Donations System by Loopus
CVE-2025-58956
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 September 2025
What is CVE-2025-58956?
A Cross-Site Request Forgery (CSRF) vulnerability in the Loopus WP Attractive Donations System could potentially allow attackers to perform unauthorized actions on behalf of users. This vulnerability involves exploiting the plugin's lack of proper verification for user actions, leading to a scenario where an attacker could execute commands through a crafted request. If successfully exploited, this vulnerability can lead to additional security issues such as Stored XSS, compromising sensitive user data and undermining application integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Attractive Donations System < 1.29
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved