CVE-2025-2797: Woffice Core <= 5.4.21 - Cross-Site Request Forgery to User Registration Approval
The Woffice Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.4.21. This is due to missing or incorrect nonce validation on the 'wofficehandleuserapprovalactions' function. This makes it possible for unauthenticated attackers to approve registration for any user via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2797?
The severity of CVE-2025-2797 is classified as a high risk due to its potential for Cross-Site Request Forgery attacks.
How do I fix CVE-2025-2797?
To fix CVE-2025-2797, you should update the Woffice Core plugin for WordPress to version 5.4.22 or later.
What systems are affected by CVE-2025-2797?
CVE-2025-2797 affects all versions of the Woffice Core plugin for WordPress up to and including version 5.4.21.
What attack vectors are associated with CVE-2025-2797?
CVE-2025-2797 can be exploited through unauthenticated Cross-Site Request Forgery attacks due to missing or incorrect nonce validation.
Who is the vendor for CVE-2025-2797?
The vendor for CVE-2025-2797 is Woffice, which develops the Woffice Core plugin for WordPress.