CVE-2025-47459: WordPress WP Fundraising Donation and Crowdfunding Platform plugin <= 1.7.3 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Roxnor FundEngine wp-fundraising-donation allows Cross Site Request Forgery.This issue affects FundEngine: from n/a through <= 1.7.3.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in XpeedStudio WP Fundraising Donation and Crowdfunding Platform allows Cross Site Request Forgery. This issue affects WP Fundraising Donation and Crowdfunding Platform: from n/a through 1.7.3.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47459?
CVE-2025-47459 is classified as a high severity Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2025-47459?
To fix CVE-2025-47459, upgrade the XpeedStudio WP Fundraising Donation and Crowdfunding Platform to version 1.7.4 or later.
What product is affected by CVE-2025-47459?
CVE-2025-47459 affects the XpeedStudio WP Fundraising Donation and Crowdfunding Platform versions up to and including 1.7.3.
What type of vulnerability is CVE-2025-47459?
CVE-2025-47459 is a Cross-Site Request Forgery (CSRF) vulnerability that can allow unauthorized actions on behalf of users.
Is CVE-2025-47459 specific to certain versions?
Yes, CVE-2025-47459 specifically affects versions of the XpeedStudio WP Fundraising Donation and Crowdfunding Platform from n/a through 1.7.3.