CVE-2025-63030: WordPress New User Approve plugin <= 3.2.3 - Cross Site Request Forgery (CSRF) vulnerability
Published Dec 9, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal New User Approve new-user-approve allows Cross Site Request Forgery.This issue affects New User Approve: from n/a through <= 3.2.3.
Affected Software
1 affected component
wordpress/new-user-approve<=3.2.3
Event History
Dec 9, 2025
CVE Published
via MITRE·02:52 PM
Data Sourced
via MITRE·02:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-63030?
CVE-2025-63030 is classified as a high-severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2025-63030?
To fix CVE-2025-63030, update the New User Approve plugin to version 3.2.1 or later.
3
Which versions of New User Approve are affected by CVE-2025-63030?
CVE-2025-63030 affects New User Approve versions from n/a up to and including 3.2.0.
4
What is Cross-Site Request Forgery in the context of CVE-2025-63030?
Cross-Site Request Forgery (CSRF) allows an attacker to make unauthorized requests on behalf of a user.
5
Is there a workaround for CVE-2025-63030 if I cannot update?
If updating is not an option, consider disabling the New User Approve plugin temporarily to mitigate the CSRF risk.