CVE-2025-49291: WordPress Calculated Fields Form plugin <= 5.3.58 - Cross Site Request Forgery (CSRF) Vulnerability
Published Jun 6, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Cross Site Request Forgery.This issue affects Calculated Fields Form: from n/a through <= 5.3.58.
Affected Software
3 affected components
CodePeople Calculated Fields Form>=n/a, <=5.3.58
WordPress Calculated Fields Form<=5.3.58
CodePeople Calculated Fields Form Wordpress<5.3.59
Remediation
Information
Update the WordPress Calculated Fields Form plugin to the latest available version (at least 5.3.59).
Event History
Jun 6, 2025
CVE Published
via MITRE·12:53 PM
Data Sourced
via MITRE·12:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-49291?
CVE-2025-49291 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to unauthorized actions being performed on behalf of authenticated users.
2
How do I fix CVE-2025-49291?
To fix CVE-2025-49291, update the Calculated Fields Form plugin to version 5.3.59 or later.
3
What versions of the Calculated Fields Form are affected by CVE-2025-49291?
CVE-2025-49291 affects Calculated Fields Form versions from n/a through 5.3.58.
4
Who is the vendor for the affected software in CVE-2025-49291?
The vendor for the affected software in CVE-2025-49291 is CodePeople.
5
What type of vulnerability is CVE-2025-49291?
CVE-2025-49291 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.