Cross-Site Request Forgery Vulnerability in Ultimate Blogroll Plugin for WordPress
CVE-2025-9881

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
12 September 2025

What is CVE-2025-9881?

The Ultimate Blogroll plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF) due to improper nonce validation in its functions. This vulnerability allows unauthenticated attackers to exploit the plugin by sending forged requests that manipulate settings or inject malicious scripts, contingent upon tricking an administrator into executing an action, such as clicking a deceptive link. This presents significant security risks, as it could lead to unauthorized changes and compromised site integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Ultimate Blogroll * <= 2.5.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JohSka
.