CVE-2025-2247: WP-PManager <= 1.2 - Category Deletion via CSRF
Published May 15, 2025
·Updated
The WP-PManager WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Affected Software
2 affected components
WP-PManager WP-PManager<=1.2
Mantus667 Wp-pmanager Wordpress<=1.2
Event History
May 15, 2025
CVE Published
via MITRE·08:07 PM
Data Sourced
via MITRE·08:07 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-2247?
CVE-2025-2247 has a medium severity rating due to the lack of CSRF protection in the WP-PManager plugin.
2
How do I fix CVE-2025-2247?
To fix CVE-2025-2247, update the WP-PManager plugin to a version that includes CSRF protection.
3
What type of attack does CVE-2025-2247 facilitate?
CVE-2025-2247 facilitates Cross-Site Request Forgery (CSRF) attacks on the WordPress admin settings.
4
Who is affected by CVE-2025-2247?
Users of the WP-PManager plugin version 1.2 and below are affected by CVE-2025-2247.
5
Can CVE-2025-2247 be exploited remotely?
Yes, CVE-2025-2247 can be exploited remotely by attackers who can craft a malicious request targeting an authenticated admin user.