CVE-2025-54010: WordPress FluentSnippets plugin <= 10.50 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSnippets allows Cross Site Request Forgery. This issue affects FluentSnippets: from n/a through 10.50.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSnippets easy-code-manager allows Cross Site Request Forgery.This issue affects FluentSnippets: from n/a through <= 10.50.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54010?
CVE-2025-54010 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can lead to unauthorized actions being performed on behalf of the user.
How do I fix CVE-2025-54010?
To resolve CVE-2025-54010, update the Shahjahan Jewel FluentSnippets to a version higher than 10.50.
What versions are affected by CVE-2025-54010?
CVE-2025-54010 affects Shahjahan Jewel FluentSnippets versions up to and including 10.50.
What are the potential impacts of CVE-2025-54010?
The impact of CVE-2025-54010 includes the potential for attackers to execute unauthorized commands on behalf of authenticated users.
Is CVE-2025-54010 specific to certain platforms?
CVE-2025-54010 specifically affects FluentSnippets used in Shahjahan Jewel and WordPress environments.