CVE-2025-32249: WordPress DirectoryPress Plugin <= 3.6.22 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in designinvento DirectoryPress allows Cross Site Request Forgery. This issue affects DirectoryPress: from n/a through 3.6.19.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Designinvento DirectoryPress directorypress allows Cross Site Request Forgery.This issue affects DirectoryPress: from n/a through <= 3.6.22.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32249?
CVE-2025-32249 is classified as a moderate severity Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2025-32249?
To fix CVE-2025-32249, you should update DirectoryPress to version 3.6.20 or later.
Which versions of DirectoryPress are affected by CVE-2025-32249?
CVE-2025-32249 affects DirectoryPress versions from n/a up to and including 3.6.19.
What kind of attack does CVE-2025-32249 enable?
CVE-2025-32249 enables Cross-Site Request Forgery (CSRF) attacks, allowing unauthorized actions to be performed on behalf of a user.
Who is impacted by CVE-2025-32249?
Users of DirectoryPress versions up to 3.6.19 are impacted by CVE-2025-32249 and should take immediate action to mitigate the risk.