Cross-Site Request Forgery in WP Attractive Donations System by Loopus
CVE-2025-58956

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2025

What is CVE-2025-58956?

A Cross-Site Request Forgery (CSRF) vulnerability in the Loopus WP Attractive Donations System could potentially allow attackers to perform unauthorized actions on behalf of users. This vulnerability involves exploiting the plugin's lack of proper verification for user actions, leading to a scenario where an attacker could execute commands through a crafted request. If successfully exploited, this vulnerability can lead to additional security issues such as Stored XSS, compromising sensitive user data and undermining application integrity.

Affected Version(s)

WP Attractive Donations System < 1.29

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bibek Dhakal (Patchstack Alliance)
.
CVE-2025-58956 : Cross-Site Request Forgery in WP Attractive Donations System by Loopus