7.5
CVSSv3

CVE-2025-2111

CVSSv4: NA | CVSSv3: 7.5 | CVSSv2: NA | VMScore: 850 | EPSS: 0.00018 | KEV: Not Included
Published: 19/04/2025 Updated: 21/04/2025

Vulnerability Summary

Cross-Site Request Forgery in WordPress Insert Headers And Footers Plugin to 3.1.1

The Insert Headers And Footers WordPress plugin (up to version 3.1.1) has a Cross-Site Request Forgery (CSRF) vulnerability in the 'custom_plugin_set_option' function. The vulnerability stems from missing or incorrect nonce validation, which allows unauthenticated attackers to update site options by tricking an administrator into performing a specific action like clicking a link. Attackers can potentially change the default registration role to administrator and enable user registration, ultimately gaining administrative access to the vulnerable WordPress site. However, the 'WPBRIGADE_SDK__DEV_MODE' constant must be set to 'true' to exploit this security weakness.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hiddenpearls insert headers and footers