Cross-Site Request Forgery in WP Attractive Donations System by Loopus
CVE-2025-58956
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 September 2025
What is CVE-2025-58956?
A Cross-Site Request Forgery (CSRF) vulnerability in the Loopus WP Attractive Donations System could potentially allow attackers to perform unauthorized actions on behalf of users. This vulnerability involves exploiting the plugin's lack of proper verification for user actions, leading to a scenario where an attacker could execute commands through a crafted request. If successfully exploited, this vulnerability can lead to additional security issues such as Stored XSS, compromising sensitive user data and undermining application integrity.
Affected Version(s)
WP Attractive Donations System < 1.29