Cross-Site Request Forgery Vulnerability in yContributors Plugin for WordPress
CVE-2025-6041
6.1MEDIUM
What is CVE-2025-6041?
The yContributors plugin for WordPress contains a security flaw that enables Cross-Site Request Forgery (CSRF) attacks due to inadequate nonce validation on the administration page. This vulnerability permits unauthenticated attackers to manipulate settings and inject harmful scripts, provided they can deceive a site administrator into activating a malicious link. It is crucial for administrators utilizing this plugin to implement necessary security measures to protect their sites from potential exploitation.