CVE-2025-66064: WordPress Giveaways and Contests by RafflePress plugin <= 1.12.20 - Cross Site Request Forgery (CSRF) vulnerability
Published Nov 21, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Giveaways and Contests by RafflePress rafflepress allows Cross Site Request Forgery.This issue affects Giveaways and Contests by RafflePress: from n/a through <= 1.12.20.
Affected Software
1 affected component
RafflePress Giveaways and Contests<=1.12.20
Event History
Nov 21, 2025
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-66064?
CVE-2025-66064 is a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How does CVE-2025-66064 affect the Giveaways and Contests by RafflePress?
CVE-2025-66064 allows attackers to perform unauthorized actions on behalf of legitimate users.
3
How do I fix CVE-2025-66064?
To fix CVE-2025-66064, update the Giveaways and Contests by RafflePress plugin to the latest version above 1.12.20.
4
Which versions of RafflePress are affected by CVE-2025-66064?
CVE-2025-66064 affects all versions of RafflePress Giveaways and Contests up to and including 1.12.20.
5
What mitigation strategies can be implemented for CVE-2025-66064?
Mitigation strategies include implementing token validation on forms to prevent CSRF attacks.