Cross-Site Request Forgery Vulnerability in Jory Hogeveen's Off-Canvas Sidebars & Menus
CVE-2025-62891
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 October 2025
What is CVE-2025-62891?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Off-Canvas Sidebars & Menus (Slidebars) plugin developed by Jory Hogeveen, enabling attackers to exploit the plugin's functionality without user consent. This security issue affects all versions from n/a up to and including version 0.5.8.5, potentially allowing unauthorized actions to be performed on behalf of a logged-in user, thereby compromising site integrity and user data.
Affected Version(s)
Off-Canvas Sidebars & Menus (Slidebars) 0 <= 0.5.8.5