5.4
CVSSv3

CVE-2025-2163

CVSSv4: NA | CVSSv3: 5.4 | CVSSv2: NA | VMScore: 640 | EPSS: 0.00019 | KEV: Not Included
Published: 15/03/2025 Updated: 28/03/2025

Vulnerability Summary

Cross-Site Request Forgery in Zoorum WordPress Plugin Allows Unauthorized Settings Modification

The Zoorum Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9. This is due to missing or incorrect nonce validation on the zoorum_set_options() function. This makes it possible for unauthenticated malicious users to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Vulnerable Product Search on Vulmon Subscribe to Product

zoorum zoorum comments