CVE-2025-57931: WordPress Popup box plugin <= 5.5.4 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box allows Cross Site Request Forgery.This issue affects Popup box: from n/a through 5.5.4.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box ays-popup-box allows Cross Site Request Forgery.This issue affects Popup box: from n/a through <= 5.5.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57931?
CVE-2025-57931 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that poses a risk to data integrity.
How do I fix CVE-2025-57931?
To fix CVE-2025-57931, update the Ays Pro Popup box to version 5.5.5 or later, where the vulnerability has been resolved.
What impacts does CVE-2025-57931 have on users?
CVE-2025-57931 can allow attackers to perform unauthorized actions on behalf of authenticated users without their consent.
Which versions are affected by CVE-2025-57931?
CVE-2025-57931 affects Ays Pro Popup box versions up to and including 5.5.4.
Is CVE-2025-57931 specific to certain platforms?
CVE-2025-57931 is specifically noted for affecting the Ays Pro Popup box and the WordPress Popup box plugin.