CVE-2025-57885: WordPress Fluent Support Plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel Fluent Support allows Cross Site Request Forgery. This issue affects Fluent Support: from n/a through 1.9.1.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Cross Site Request Forgery.This issue affects Fluent Support: from n/a through <= 1.9.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57885?
CVE-2025-57885 is a medium severity Cross-Site Request Forgery vulnerability.
How does CVE-2025-57885 affect users?
CVE-2025-57885 allows attackers to perform unauthorized actions on behalf of authenticated users.
How do I fix CVE-2025-57885?
To fix CVE-2025-57885, update Shahjahan Jewel Fluent Support to version 1.9.2 or later.
Who is affected by CVE-2025-57885?
Users of Shahjahan Jewel Fluent Support and WordPress Fluent Support Plugin versions up to 1.9.1 are affected by CVE-2025-57885.
What is Cross-Site Request Forgery as related to CVE-2025-57885?
Cross-Site Request Forgery in CVE-2025-57885 refers to an attack that tricks a user into executing unwanted actions on a different site.