CSRF Vulnerability in AR For WordPress by Webandprint
CVE-2025-60156

9.6CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
26 September 2025

What is CVE-2025-60156?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the AR For WordPress plugin by Webandprint, which could allow an attacker to upload a malicious web shell to the web server. This issue impacts all versions from n/a through 7.98, posing a significant risk to the integrity of web applications that utilize this plugin.

Affected Version(s)

AR For WordPress <= 7.98

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abu Hurayra (Patchstack Alliance)
.
CVE-2025-60156 : CSRF Vulnerability in AR For WordPress by Webandprint