First published: Thu Jan 16 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Cornea Alexandru Category Custom Fields allows Cross Site Request Forgery.This issue affects Category Custom Fields: from n/a through 1.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cornea Alexandru Category Custom Fields | <=1.0 | |
WordPress Category Custom Fields | <=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23822 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can lead to unauthorized actions being performed on behalf of an authenticated user.
To fix CVE-2025-23822, update the Cornea Alexandru Category Custom Fields plugin to version 1.1 or higher, as earlier versions are vulnerable.
CVE-2025-23822 affects Cornea Alexandru Category Custom Fields versions up to and including 1.0.
CVE-2025-23822 can enable attackers to perform unauthorized actions on behalf of users without their consent or knowledge.
Yes, exploitation of CVE-2025-23822 requires the attacker to be able to trick an authenticated user into performing actions that they did not intend.