Cross-Site Request Forgery Vulnerability in MicroPayments Plugin for WordPress
CVE-2025-5937
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 June 2025
What is CVE-2025-5937?
The MicroPayments plugin for WordPress suffers from a Cross-Site Request Forgery vulnerability due to improper nonce validation in the adminOptions() function. This flaw allows unauthenticated attackers to potentially alter the plugin's configuration through malicious requests, particularly if they can deceive a site administrator into executing an unintended action, such as clicking a deceptive link. All versions of the plugin up to and including 3.2.0 are affected, highlighting a crucial security need for users of this plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MicroPayments β Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet * <= 3.2.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved