WP CSRF JUN 2025

WP CSRF JUN 2025: 101 Bold WP Cross-Site Request Forgery (infographic)

Sponsored by:

😍 owlpower.eu managed AI services - 🤖️ use advanced AI models for your 🌐️ WP & 🛒️ Woo: generate content, images, forms, and more, tailored directly for your domain and business niche.

Be informed about the latest WP Cross-Site Request Forgery, identified and reported publicly. As these WP CSRF JUN 2025 vulnerabilities have a severe negative impact on any WordPress Security, consider our security audit. It is a -60% DECREASE, compared to previous month, as specifically targeted Cross-Site Request Forgeries. Consider for your online safety, a managed WP/Woo Security AUDIT, – OR – switching with a TOP10LIST alternative WP Security Plugin - OR - Hire professionals for managed Security.

WP CSRF JUN 2025
Contact your online project manager:

Order managed services

Fast forward into your future: your business is on autopilot, yet you are in control. Your business niche integrations still work, your partners and your customers are happy.

There hasn’t been a crisis or “online emergency” in ages, and all your reports are OK and green. Whimsical? The future is already here. Step into your future today.

WP CSRF JUN 2025

As these Cross-Site Request Forgeries cases from publicly reported vulnerable plugins are on your domain, it opens Pandora’s box from a security point of view. The following cases made headlines PUBLICLY just last month in the WP CSRF JUN 2025 & WP Cross-Site Request Forgery category:

4stats Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
워드프레스 결제 심플페이 Cross-Site Request Forgery (CSRF)
Abundatrade Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Accept Donations with PayPal Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Advanced Reorder Image Text Slider Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Affiliates Manager Google reCAPTCHA Integration Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
AHAthat Cross-Site Request Forgery (CSRF) and AHA Page Deletion (BAC)
Alink Tap Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
AlT Monitoring Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Audio Comments Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
AWcode Toolkit Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Awin – Advertiser Tracking for WooCommerce Cross-Site Request Forgery (CSRF) and Product Feed Regeneration
BabelZ Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Beacon Lead Magnets and Lead Capture Cross-Site Request Forgery (CSRF)
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP Cross-Site Request Forgery (CSRF)
BTEV Settings Update (BAC) from Cross-Site Request Forgery (CSRF)
Challan Cross-Site Request Forgery (CSRF) and Privilege Escalation (BAC)
Competition Form Competition Deletion from Cross-Site Request Forgery (CSRF)
Connexion Logs Log Deletion from Cross-Site Request Forgery (CSRF)
Contact Form Widget Cross-Site Request Forgery (CSRF)
Contribuinte Checkout Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Cool Author Box Cross-Site Request Forgery (CSRF)
Credova_Financial Cross-Site Request Forgery (CSRF)
CSS3 Accordions for WordPress Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Custom Author Base Settings Update (BAC) from Cross-Site Request Forgery (CSRF)
DoFollow Case by Case Cross-Site Request Forgery (CSRF)
Dynamic Pricing & Discounts Lite for WooCommerce Cross-Site Request Forgery (CSRF)
EasyMe Connect Cross-Site Request Forgery (CSRF)
Easy PayPal Events Cross-Site Request Forgery (CSRF)
EKC Tournament Manager Create Tournaments/Teams from Cross-Site Request Forgery (CSRF)
Element Pack Pro Cross-Site Request Forgery (CSRF)
ELI's Related Posts Footer Links and Widget Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Falang multilanguage Cross-Site Request Forgery (CSRF)
GamiPress Reset User GamiPress User Data Removal from Cross-Site Request Forgery (CSRF)
GDPR Cookie Consent Bulk Delete from Cross-Site Request Forgery (CSRF)
GPT3 AI Content Writer Cross-Site Request Forgery (CSRF) and Prompt Generation
Graphina Cross-Site Request Forgery (CSRF) and Local File Inclusion (LFi)
GS Logo Slider Settings Update (BAC) from Cross-Site Request Forgery (CSRF)
Hash Form Cross-Site Request Forgery (CSRF)
Import Export For WooCommerce Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Japanized For WooCommerce Cross-Site Request Forgery (CSRF)
JavaScript Logic Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
JSP Store Locator Deletion from Missing Cross-Site Request Forgery (CSRF)
LessButtons Social Sharing and Statistics Cross-Site Request Forgery (CSRF) and Settings Change (BAC)
Listamester Cross-Site Request Forgery (CSRF)
LiveAgent Cross-Site Request Forgery (CSRF)
MapFig Studio Cross-Site Scripting (XSS) from Cross-Site Request Forgery (CSRF)
Martins Free Monetized Ad Exchange Network Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Nokaut Offers Box Plugin Reset from Cross-Site Request Forgery (CSRF)
Ntz Antispam Settings Update (BAC) from Cross-Site Request Forgery (CSRF)
occupancyplan Cross-Site Request Forgery (CSRF) and SQL Injection (SQLi)
Offload Videos – Bunny.net, AWS S3 Cross-Site Request Forgery (CSRF)
Pays – WooCommerce Payment Gateway Cross-Site Request Forgery (CSRF)
PeoplePond Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Pixel WordPress Form BuilderPlugin & Autoresponder Cross-Site Request Forgery (CSRF)
Product Code for WooCommerce Cross-Site Request Forgery (CSRF) and Database Update
Product Quantity Dropdown For Woocommerce Cross-Site Request Forgery (CSRF) and Settings Change (BAC)
PW WooCommerce Bulk Edit Cross-Site Request Forgery (CSRF)
QuickCal Cross-Site Request Forgery (CSRF) and Privilege Escalation (BAC)
QuickCal Cross-Site Request Forgery (CSRF) and Privilege Escalation (BAC)
reCAPTCHA for all Cross-Site Request Forgery (CSRF)
Rootspersona Cross-Site Request Forgery (CSRF)
Salon booking system Cross-Site Request Forgery (CSRF) and Arbitrary Content Deletion
SEO Flow by LupsOnline Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Seven Stars Theme Cross-Site Request Forgery (CSRF)
Seznam Webmaster Cross-Site Request Forgery (CSRF)
ShayanWeb Admin FontChanger Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Sidebar Manager Light Cross-Site Request Forgery (CSRF)
Simple calendar for Elementor Cross-Site Request Forgery (CSRF)
Simple Giveaways Cross-Site Request Forgery (CSRF)
Simple Nav Archives Settings Update (BAC) from Cross-Site Request Forgery (CSRF)
Simple Page Access Restriction Cross-Site Request Forgery (CSRF) from Multiple Parameters
Smaily for WP Cross-Site Request Forgery (CSRF)
Smooth Gallery Replacement Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Soccer Live Scores Cross-Site Request Forgery (CSRF)
Spare Theme Cross-Site Request Forgery (CSRF)
Spiritual Gifts Survey Unauthenticated Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Supertext Translation and Proofreading Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
tarteaucitron.js for WordPress Cross-Site Scripting (XSS) from Cross-Site Request Forgery (CSRF)
theMarketer Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Travelpayouts Settings Update (BAC) from Cross-Site Request Forgery (CSRF)
TrueBooker Cross-Site Request Forgery (CSRF)
TwitterPosts Settings Update (BAC) from Cross-Site Request Forgery (CSRF)
Ultimate WP Mail Cross-Site Request Forgery (CSRF)
User Profile Meta Manager Cross-Site Request Forgery (CSRF) and Privilege Escalation (BAC)
ValidateCertify Cross-Site Request Forgery (CSRF)
Web Accessibility with Max Access Cross-Site Request Forgery (CSRF)
Wholesale Market Settings Update (BAC) from Cross-Site Request Forgery (CSRF)
Widgets Reset Settings Update (BAC) from Cross-Site Request Forgery (CSRF)
Wiki Embed Cross-Site Request Forgery (CSRF) and Settings Change (BAC)
WordPress连接微博 Cross-Site Scripting (XSS) from Cross-Site Request Forgery (CSRF)
WP2LEADS Cross-Site Request Forgery (CSRF)
WP Compress Cross-Site Request Forgery (CSRF)
WP Fundraising Donation and Crowdfunding Platform Cross-Site Request Forgery (CSRF)
WP Hotel Booking Cross-Site Request Forgery (CSRF)
WP Mapa Politico España Cross-Site Request Forgery (CSRF) and Settings Change (BAC)
WP-PManager Category Deletion from Cross-Site Request Forgery (CSRF)
WP Podcasts Manager Cross-Site Request Forgery (CSRF)
WPSpeed Cross-Site Request Forgery (CSRF)
WP Ultimate Tours Builder Cross-Site Request Forgery (CSRF)
Year Make Model Search for WooCommerce Cross-Site Request Forgery (CSRF) and Settings Change (BAC)
WordPress CSRF & Cross-Site Request Forgery reported in 2023: 949
WordPress CSRF & Cross-Site Request Forgery reported in 2024: 876
WordPress CSRF & Cross-Site Request Forgery reported in 2025: 971
Contact your online project manager:

Get managed security

Fast forward 2-3 years: your business is on autopilot, yet you are in control. Your website is humming along, leads & customers are rolling in.

There hasn’t been a crisis or “website emergency” in ages, and all your charts are pointing up and to the right. Whimsical? The future is already here. Step into your future today.

Table Of Contents


A cup of coffee makes a difference ...

How wonderful would be to simply let others take care of your chores? We absolutely understand why you would want that. This is why we propose this unique campaign: the price of a premium cup of coffee per week, for your first managed service.
Start simply by contacting us with your selections:

ultrai.ae managed online administration © 2023 - 2025 – All rights reserved
We’re on an empowering mission for customers, who desire not to be transformed forcefully into IT experts.
ultrai.ae