CVE-2025-25086: WordPress Secret Meta plugin <= 1.2.1 - CSRF to Reflected Cross Site Scripting (XSS) vulnerability
Published Mar 27, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in WPDeveloper Secret Meta facebook-secret-meta allows Reflected XSS.This issue affects Secret Meta: from n/a through <= 1.2.1.
Affected Software
1 affected component
WPDeveloper Secret Meta<=1.2.1
Event History
Mar 27, 2025
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-25086?
CVE-2025-25086 is classified as a moderate severity vulnerability due to its potential for exploitation through Cross-Site Request Forgery leading to Reflected XSS.
2
How do I fix CVE-2025-25086?
To fix CVE-2025-25086, update the WPDeveloper Secret Meta plugin to version 1.2.2 or later.
3
What specific versions of Secret Meta are affected by CVE-2025-25086?
CVE-2025-25086 affects versions of WPDeveloper Secret Meta up to and including 1.2.1.
4
What type of vulnerability is CVE-2025-25086?
CVE-2025-25086 is a Cross-Site Request Forgery (CSRF) vulnerability that allows for Reflected Cross-Site Scripting (XSS).
5
Who is the vendor for the affected software in CVE-2025-25086?
The vendor for the affected software in CVE-2025-25086 is WPDeveloper.