Cross-Site Request Forgery Vulnerability in Easy Property Listings by Merv Barrett
CVE-2025-62112
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 December 2025
What is CVE-2025-62112?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Easy Property Listings plugin developed by Merv Barrett. This flaw allows an unauthorized attacker to perform actions on behalf of a legitimate user without their consent. Specifically, this issue affects versions of the plugin from its release up to 2.2.1, potentially compromising user accounts and data integrity. It is crucial for users to update their installation to mitigate the risks posed by this vulnerability.
Affected Version(s)
Import into Easy Property Listings 0 <= 2.2.1