CVE-2025-31457: WordPress LWS SMS plugin <= 2.4.1 - Cross Site Request Forgery (CSRF) Vulnerability
Published Mar 28, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Aurélien LWS LWS SMS lws-sms allows Cross Site Request Forgery.This issue affects LWS SMS: from n/a through <= 2.4.1.
Affected Software
1 affected component
LWS LWS SMS<=2.4.1
Event History
Mar 28, 2025
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-31457?
CVE-2025-31457 is classified as a medium severity Cross-Site Request Forgery vulnerability.
2
How do I fix CVE-2025-31457?
To fix CVE-2025-31457, it is recommended to update LWS SMS to version 2.4.2 or later.
3
What types of attacks are possible with CVE-2025-31457?
CVE-2025-31457 allows attackers to perform unwanted actions on behalf of authenticated users, potentially leading to unauthorized data access.
4
Which versions of LWS SMS are affected by CVE-2025-31457?
CVE-2025-31457 affects versions of LWS SMS from n/a through 2.4.1.
5
Is authentication required to exploit CVE-2025-31457?
Yes, an attacker typically needs to have access to an authenticated user's session to exploit CVE-2025-31457.