CVE-2025-30833: WordPress Verge3D Publishing and E-Commerce Plugin <= 4.8.2 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Soft8Soft LLC Verge3D verge3d allows Cross Site Request Forgery.This issue affects Verge3D: from n/a through <= 4.8.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30833?
CVE-2025-30833 has been classified with a high severity as it allows for Cross-Site Request Forgery (CSRF) attacks.
How do I fix CVE-2025-30833?
To fix CVE-2025-30833, you should update Soft8Soft Verge3D and the Verge3D Publishing and E-Commerce Plugin to the latest version beyond 4.8.2.
Who is affected by CVE-2025-30833?
CVE-2025-30833 affects Soft8Soft Verge3D versions up to 4.8.2 and the WordPress Verge3D Publishing and E-Commerce Plugin up to 4.8.2.
What kind of attack can CVE-2025-30833 facilitate?
CVE-2025-30833 can facilitate Cross-Site Request Forgery (CSRF) attacks, allowing unauthorized actions on behalf of a user.
Is CVE-2025-30833 exploitable without user interaction?
Yes, CVE-2025-30833 can be exploited without user interaction, as it involves making unauthorized requests to the web application.