Cross-Site Request Forgery Vulnerability in Restore Permanently Delete Post or Page Data Plugin for WordPress
CVE-2025-7839
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 August 2025
What is CVE-2025-7839?
The Restore Permanently Delete Post or Page Data plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF). This vulnerability occurs due to inadequate nonce validation in the rp_dpo_dpa_ajax_dp_delete_data() function, allowing unauthenticated attackers to manipulate actions on the site. By tricking an administrator into executing a forged request, an attacker could delete posts or pages without proper authorization. To mitigate this threat, it is crucial for site owners to update the plugin to the latest version and implement appropriate security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Restore Permanently delete Post or Page Data * <= 1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved