CVE-2025-54672: WordPress Photo Engine Plugin plugin <= 6.4.3 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Jordy Meow Photo Engine allows Cross Site Request Forgery. This issue affects Photo Engine: from n/a through 6.4.3.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Jordy Meow Photo Engine wplr-sync allows Cross Site Request Forgery.This issue affects Photo Engine: from n/a through <= 6.4.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54672?
CVE-2025-54672 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that could allow attackers to perform unauthorized actions.
How do I fix CVE-2025-54672?
To mitigate CVE-2025-54672, update the Jordy Meow Photo Engine or WordPress Photo Engine Plugin to the latest version that addresses this vulnerability.
What versions are affected by CVE-2025-54672?
CVE-2025-54672 affects versions of Jordy Meow Photo Engine from n/a through 6.4.3.
What potential impact does CVE-2025-54672 have on users?
CVE-2025-54672 could allow attackers to perform actions on behalf of authenticated users without their consent.
Is CVE-2025-54672 specific to any platforms?
CVE-2025-54672 is specifically found in Jordy Meow Photo Engine and the WordPress Photo Engine Plugin.