CVE-2025-49345: WordPress WP-EasyArchives plugin <= 3.1.2 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in mg12 WP-EasyArchives allows Stored XSS.This issue affects WP-EasyArchives: from n/a through 3.1.2.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in mg12 WP-EasyArchives wp-easyarchives allows Stored XSS.This issue affects WP-EasyArchives: from n/a through <= 3.1.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49345?
CVE-2025-49345 is classified as a high-severity Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2025-49345?
To fix CVE-2025-49345, update your WP-EasyArchives plugin to the latest version beyond 3.1.2.
What versions are affected by CVE-2025-49345?
CVE-2025-49345 affects WP-EasyArchives versions from n/a up to and including version 3.1.2.
What type of vulnerability is CVE-2025-49345?
CVE-2025-49345 is a Cross-Site Request Forgery (CSRF) vulnerability that allows for stored Cross-Site Scripting (XSS).
Can CVE-2025-49345 lead to data compromise?
Yes, CVE-2025-49345 can potentially lead to data compromise through stored XSS attacks.