CVE-2025-32591: WordPress WP Abstracts Plugin <= 2.7.5 - CSRF to Stored XSS vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Kevon Adonis WP Abstracts allows Cross Site Request Forgery. This issue affects WP Abstracts: from n/a through 2.7.4.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Cross Site Request Forgery.This issue affects WP Abstracts: from n/a through <= 2.7.5.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32591?
CVE-2025-32591 is classified as a Cross-Site Request Forgery (CSRF) vulnerability affecting WP Abstracts.
How do I fix CVE-2025-32591?
To mitigate CVE-2025-32591, update WP Abstracts to version 2.7.5 or later.
What versions of WP Abstracts are affected by CVE-2025-32591?
CVE-2025-32591 affects all versions of WP Abstracts from n/a through 2.7.4.
Is CVE-2025-32591 a critical vulnerability?
While the criticality can depend on the context, CVE-2025-32591 poses a security risk that could potentially be exploited by attackers.
What type of attacks can CVE-2025-32591 facilitate?
CVE-2025-32591 can facilitate CSRF attacks, allowing unauthorized actions to be performed on behalf of users.