CVE-2025-28881: WordPress Mobile Themes plugin <= 1.1.1 - Cross Site Request Forgery (CSRF) vulnerability
Published Mar 11, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in mg12 Mobile Themes wp-mobile-themes allows Cross Site Request Forgery.This issue affects Mobile Themes: from n/a through <= 1.1.1.
Affected Software
1 affected component
Mg12 Mobile Themes (wp-mobile-themes)<=1.1.1
Event History
Mar 11, 2025
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-28881?
The severity of CVE-2025-28881 is classified as a medium risk due to its potential for Cross-Site Request Forgery.
2
How do I fix CVE-2025-28881?
To fix CVE-2025-28881, update the WordPress Mobile Themes plugin to the latest version.
3
What systems are affected by CVE-2025-28881?
CVE-2025-28881 affects WordPress Mobile Themes versions from n/a through 1.1.1.
4
What is Cross-Site Request Forgery in relation to CVE-2025-28881?
CVE-2025-28881 allows an attacker to perform actions on behalf of an authenticated user without their consent, known as Cross-Site Request Forgery.
5
How can I mitigate risks associated with CVE-2025-28881?
To mitigate risks associated with CVE-2025-28881, ensure the plugin is updated, limit user permissions, and validate user input.