CVE-2025-32610: WordPress Foliopress WYSIWYG plugin <= 2.6.18 - CSRF to Stored XSS vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in FolioVision Foliopress WYSIWYG foliopress-wysiwyg allows Cross Site Request Forgery.This issue affects Foliopress WYSIWYG: from n/a through <= 2.6.18.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Foliovision: Making the web work for you Foliopress WYSIWYG allows Cross Site Request Forgery. This issue affects Foliopress WYSIWYG: from n/a through 2.6.18.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32610?
CVE-2025-32610 has a medium severity rating due to its potential for Cross-Site Request Forgery attacks.
How do I fix CVE-2025-32610?
To fix CVE-2025-32610, update Foliopress WYSIWYG to the latest version beyond 2.6.18.
What software versions are affected by CVE-2025-32610?
CVE-2025-32610 affects Foliopress WYSIWYG versions from n/a through 2.6.18.
What type of vulnerability is CVE-2025-32610?
CVE-2025-32610 is a Cross-Site Request Forgery (CSRF) vulnerability.
Can CVE-2025-32610 lead to more serious vulnerabilities?
Yes, CVE-2025-32610 could potentially lead to stored XSS if exploited.