CVE-2025-57942: WordPress Emergency Password Reset plugin <= 9.3 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in andymoyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 9.0.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in andymoyle Emergency Password Reset emergency-password-reset allows Cross Site Request Forgery.This issue affects Emergency Password Reset: from n/a through <= 9.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57942?
CVE-2025-57942 is classified as a Cross Site Request Forgery (CSRF) vulnerability, which can lead to unauthorized actions being performed on behalf of a user.
How do I fix CVE-2025-57942?
To mitigate CVE-2025-57942, update the Emergency Password Reset plugin to version 9.4 or later, which contains the necessary security patches.
What versions are affected by CVE-2025-57942?
CVE-2025-57942 affects versions of the Emergency Password Reset plugin from version n/a up to and including version 9.3.
What kind of attack does CVE-2025-57942 facilitate?
CVE-2025-57942 enables attackers to execute Cross Site Request Forgery attacks, potentially allowing them to change user passwords without authorization.
Is any user data at risk with CVE-2025-57942?
Yes, CVE-2025-57942 can put user accounts at risk, as an attacker could exploit this vulnerability to reset user passwords and gain unauthorized access.