CVE-2025-60134: WordPress WP Media Categories Plugin <= 2.1.0 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in John James Jacoby WP Media Categories wp-media-categories allows Cross Site Request Forgery.This issue affects WP Media Categories: from n/a through <= 2.1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60134?
CVE-2025-60134 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can potentially allow unauthorized actions on behalf of authenticated users.
How do I fix CVE-2025-60134?
To mitigate CVE-2025-60134, update the WP Media Categories plugin to the latest version beyond 2.1.0.
Who is affected by CVE-2025-60134?
CVE-2025-60134 affects users of the WP Media Categories plugin versions up to and including 2.1.0.
What type of attack does CVE-2025-60134 enable?
CVE-2025-60134 enables Cross-Site Request Forgery attacks, which may result in unauthorized actions performed on user accounts.
Is user authentication required for exploitation of CVE-2025-60134?
Yes, successful exploitation of CVE-2025-60134 typically requires that the attacker tricks an authenticated user into making a malicious request.