CVE-2025-57924: WordPress Developer Plugin <= 1.2.6 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Automattic Developer allows Cross Site Request Forgery. This issue affects Developer: from n/a through 1.2.6.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Automattic Developer developer allows Cross Site Request Forgery.This issue affects Developer: from n/a through <= 1.2.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57924?
CVE-2025-57924 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can potentially lead to unauthorized actions being performed on behalf of a user.
How do I fix CVE-2025-57924?
To fix CVE-2025-57924, you should update Automattic Developer or WordPress Developer Plugin to the latest version available beyond 1.2.6.
What versions are affected by CVE-2025-57924?
CVE-2025-57924 affects Automattic Developer and WordPress Developer Plugin from versions n/a through 1.2.6.
What type of attack does CVE-2025-57924 facilitate?
CVE-2025-57924 facilitates Cross-Site Request Forgery (CSRF) attacks, allowing attackers to perform actions without the user's consent.
Who is impacted by CVE-2025-57924?
Users of Automattic Developer and WordPress Developer Plugin versions up to 1.2.6 are impacted by CVE-2025-57924.