Cross-Site Request Forgery Vulnerability in Homerunner Plugin for WordPress
CVE-2025-5932
4.3MEDIUM
What is CVE-2025-5932?
The Homerunner plugin for WordPress has a vulnerability that permits Cross-Site Request Forgery due to inadequate nonce validation in the main_settings() function. This flaw allows unauthenticated attackers to potentially alter plugin settings by tricking legitimate users, specifically site administrators, into executing a malicious action, such as clicking on a deceptive link. It is critical for users to ensure they are running the latest versions of the plugin to mitigate risks associated with this vulnerability.
Affected Version(s)
Homerunner * <= 1.0.29