Cross-Site Request Forgery Vulnerability in MicroPayments Plugin for WordPress
CVE-2025-5937
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 June 2025
What is CVE-2025-5937?
The MicroPayments plugin for WordPress suffers from a Cross-Site Request Forgery vulnerability due to improper nonce validation in the adminOptions() function. This flaw allows unauthenticated attackers to potentially alter the plugin's configuration through malicious requests, particularly if they can deceive a site administrator into executing an unintended action, such as clicking a deceptive link. All versions of the plugin up to and including 3.2.0 are affected, highlighting a crucial security need for users of this plugin.
Affected Version(s)
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet * <= 3.2.0