CVE-2025-58847: WordPress WN Flipbox Pro Plugin <= 2.1 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Yaidier WN Flipbox Pro allows Reflected XSS. This issue affects WN Flipbox Pro: from n/a through 2.1.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Yaidier WN Flipbox Pro wn-flipbox-pro allows Reflected XSS.This issue affects WN Flipbox Pro: from n/a through <= 2.1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58847?
CVE-2025-58847 is a medium severity Cross-Site Request Forgery (CSRF) vulnerability that also allows for Reflected XSS.
How do I fix CVE-2025-58847?
To fix CVE-2025-58847, you should upgrade Yaidier WN Flipbox Pro to version 2.2 or later.
What versions are affected by CVE-2025-58847?
CVE-2025-58847 affects Yaidier WN Flipbox Pro from unknown versions through 2.1.
Can CVE-2025-58847 lead to data compromise?
Yes, CVE-2025-58847 can potentially lead to data compromise through the execution of malicious requests by attackers.
Is CVE-2025-58847 specific to certain platforms?
CVE-2025-58847 specifically affects the Yaidier WN Flipbox Pro and WordPress WN Flipbox Pro Plugin.