CVE-2025-30912: WordPress Float menu plugin <= 6.1.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
Published Mar 27, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Float menu float-menu allows Cross Site Request Forgery.This issue affects Float menu: from n/a through <= 6.1.2.
Affected Software
1 affected component
Wow-Company WordPress Float menu<=6.1.2
Remediation
Information
Update the WordPress Float menu plugin to the latest available version (at least 6.1.3).
Event History
Mar 27, 2025
CVE Published
via MITRE·10:55 AM
Data Sourced
via MITRE·10:55 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-30912?
CVE-2025-30912 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2025-30912?
To mitigate CVE-2025-30912, update the Wow-Company Float menu plugin to version 6.1.3 or later.
3
What systems are affected by CVE-2025-30912?
CVE-2025-30912 affects the Wow-Company Float menu and WordPress Float menu versions up to and including 6.1.2.
4
What type of vulnerability is CVE-2025-30912?
CVE-2025-30912 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
What impact does CVE-2025-30912 have?
CVE-2025-30912 can allow attackers to perform unauthorized actions within the Float menu plugin on behalf of authenticated users.