Cross-Site Request Forgery Vulnerability in Tusko Trush Advanced Custom Fields Plugin
CVE-2025-60208
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 October 2025
What is CVE-2025-60208?
A Cross-Site Request Forgery (CSRF) vulnerability found in Tusko Trush's Advanced Custom Fields : CPT Options Pages plugin allows for object injection, potentially leading to unauthorized actions being executed on behalf of the user. This issue impacts versions of the plugin up to and including 2.0.9, posing a significant risk to websites utilizing this functionality without proper security measures.
Affected Version(s)
Advanced Custom Fields : CPT Options Pages <= n/a