CVE-2025-31828: WordPress Easy!Appointments plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
Published Apr 1, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site Request Forgery.This issue affects Easy!Appointments: from n/a through <= 1.4.2.
Affected Software
3 affected components
Easy!Appointments Easy!Appointments>=1.4.2
WordPress Easy!Appointments plugin<=1.4.2
EasyAppointments Easy\!appointments Wordpress<=1.4.2
Event History
Apr 1, 2025
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-31828?
CVE-2025-31828 is classified as a Cross-Site Request Forgery (CSRF) vulnerability which can lead to unauthorized actions on behalf of users.
2
How do I fix CVE-2025-31828?
To fix CVE-2025-31828, upgrade Easy!Appointments to the latest version that addresses the CSRF vulnerability.
3
What versions are affected by CVE-2025-31828?
CVE-2025-31828 affects Easy!Appointments version 1.4.2 and earlier.
4
What impact does CVE-2025-31828 have on users?
CVE-2025-31828 allows attackers to perform actions without user consent, potentially compromising user accounts.
5
Is CVE-2025-31828 specific to certain platforms?
CVE-2025-31828 affects both the standalone Easy!Appointments software and the WordPress Easy!Appointments plugin.