CVE-2025-49273: WordPress WP Tools plugin <= 5.24 - Cross Site Request Forgery (CSRF) Vulnerability
Published Jun 6, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi WP Tools allows Cross Site Request Forgery. This issue affects WP Tools: from n/a through 5.24.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in sminozzi WP Tools wptools allows Cross Site Request Forgery.This issue affects WP Tools: from n/a through <= 5.24.
— MITRE
Affected Software
1 affected component
Bill Minozzi WP Tools<=5.24
Remediation
Information
Update the WordPress WP Tools plugin to the latest available version (at least 5.25).
Event History
Jun 6, 2025
CVE Published
via MITRE·12:53 PM
Data Sourced
via MITRE·12:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49273?
CVE-2025-49273 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2025-49273?
The mitigation for CVE-2025-49273 involves upgrading WP Tools to version 5.25 or higher.
3
Which versions of WP Tools are affected by CVE-2025-49273?
CVE-2025-49273 affects all versions of WP Tools from n/a up to and including version 5.24.
4
What type of vulnerability is CVE-2025-49273?
CVE-2025-49273 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Who is the vendor affected by CVE-2025-49273?
CVE-2025-49273 affects the WP Tools plugin developed by Bill Minozzi.