First published: Fri Feb 07 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in FancyWP Starter Templates by FancyWP allows Cross Site Request Forgery. This issue affects Starter Templates by FancyWP: from n/a through 2.0.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
FancyWP Starter Templates | <=2.0.0 | |
FancyWP Starter Templates | <=2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25106 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can lead to unauthorized actions being taken on behalf of users.
To fix CVE-2025-25106, update the FancyWP Starter Templates plugin to version 2.0.1 or later.
CVE-2025-25106 affects all versions of FancyWP Starter Templates plugin up to and including 2.0.0.
Attackers exploiting CVE-2025-25106 can perform unauthorized actions due to the CSRF vulnerability, potentially compromising user data.
Currently, there are no publicly disclosed exploits specifically for CVE-2025-25106, but it is important to address the vulnerability promptly.