WP CSRF FEB 2025
WP Cross-Site Request Forgery
Managed Woo/WP Security Report
Be informed about the latest WP Cross-Site Request Forgery, identified and reported publicly. As these WP CSRF FEB 2025 vulnerabilities have a severe negative impact on any WordPress Security, consider our security audit.
It is a +98% INCREASE compared to previous month, as specifically targeted Cross-Site Request Forgeries. Consider for your online safety, a managed WP/Woo Security AUDIT, - OR - switching with a TOP10LIST alternative WP Security Plugin – OR – Hire us for your recurrent needs of managed WordPress Security and managed WooCommerce Security.
WHO needs managed WP security? EVERYBODY!
Today's reality needs a Web Application Firewall (WAF) plus an Intrusion Prevention System (IPS) to mitigate "gazillion" different threats in your WordPress. Get your WP Cross-Site Request Forgery Patch Management.
The following cases made headlines PUBLICLY in the WP CSRF FEB 2025 & WP Cross-Site Request Forgery category:
add custom google tag manager | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Add RSS | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Admin Cleanup | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Admin debug wordpress – enable debug | Cross-Site Request Forgery (CSRF) |
Affiliate Disclosure Statement | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
AI Scribe | Cross-Site Request Forgery (CSRF) to Settings Update (BAC) |
AI WP Writer | Cross-Site Request Forgery (CSRF) |
Altra Side Menu | Menu Deletion (BAC) from Cross-Site Request Forgery (CSRF) |
amr personalise | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Annie | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Anonymize Links | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
AnyRoad | Cross-Site Request Forgery (CSRF) |
Apply with LinkedIn buttons | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Attire Blocks | Cross-Site Request Forgery (CSRF) |
Auphonic Importer | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Autocompleter | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Auto FTP | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Automate Hub | Cross-Site Request Forgery (CSRF) to Activation Status Update (BAC) |
Background Control | Cross-Site Request Forgery (CSRF) and File Deletion (BAC) |
Better Protected Pages | Cross-Site Request Forgery (CSRF) |
Bible Embed | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Binary MLM Woocommerce | Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS) |
Blogger Image Import | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Board Election | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Book a Place | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
BSK Forms Blacklist | Cross-Site Request Forgery (CSRF) and SQL Injection (SQLi) |
Bubble Menu – circle floating menu | Cross-Site Request Forgery (CSRF) |
Build Private Store For Woocommerce | Cross-Site Request Forgery (CSRF) |
Bulk Me Now! | Message Deletion (BAC) from Cross-Site Request Forgery (CSRF) |
Bus Ticket Booking with Seat Reservation | Cross-Site Request Forgery (CSRF) |
Button Generator – easily Button Builder | Cross-Site Request Forgery (CSRF) |
Call me Now | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Call Now Button | Cross-Site Request Forgery (CSRF) |
Category Custom Fields | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Chative Live chat and Chatbot | Cross-Site Request Forgery (CSRF)via add_chative_widget_action Function |
Chatter | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
CJ Custom Content | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
CNZZ&51LA for WordPress | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Comment-Emailer | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Content Security Policy Pro | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Cookie Consent & Autoblock for GDPR/CCPA | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Copyright Safeguard Footer Notice | Cross-Site Request Forgery (CSRF) and Cross-Site Request Forgery (CSRF) |
Counter Box | Cross-Site Request Forgery (CSRF) and Settings Change (BAC) |
Curated Search | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Custom List Table Example | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Custom Post | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Custom Post Type Lockdown | Cross-Site Request Forgery (CSRF) and Privilege Escalation (BAC) |
Custom Widget Classes | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Debt Calculator | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
DF Draggable | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Dynamic URL SEO | Cross-Site Request Forgery (CSRF) |
Dyn Business Panel | Cross-Site Scripting (XSS) from Cross-Site Request Forgery (CSRF) |
Easy Tynt | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
ECT Add and Cart Button | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Elevio | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Email on Publish | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
EmailShroud | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Error Notification | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Essential Real Estate | Cross-Site Request Forgery (CSRF) |
Estatebud – Properties & Listings | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Extra Options – Favicons | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Fare Calculator | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Find Your Reps | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
FlashCounter | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Floatbox Plus | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
FluentSMTP | Cross-Site Request Forgery (CSRF) |
Flying Twitter Birds | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Free MailClient FMC | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Full Circle | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
GDReseller | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Genki Announcement | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Geotagged Media | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
go Social | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
GravatarLocalCache | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Hack me if you can | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Herd Effects | Cross-Site Request Forgery (CSRF) and Settings Change (BAC) |
Hotspots Analytics | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
HTTP and HTTPS link Change (BAC) r by Eyga.net | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Import Users and MailChimp | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Instabot | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Internal Link Builder | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
iSpring Embedder | Cross-Site Request Forgery (CSRF) and File Upload (BAC) |
Issuu Panel | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
JK Html and Pdf | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Job Board Manager | Cross-Site Request Forgery (CSRF) |
Kapost | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
KBucket | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Laika Pedigree Tree | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
ldap_login_password_and_role_manager | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Len Slider | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Linear | Cross-Site Request Forgery (CSRF) to Cache Reset (BAC) |
Linet ERP-Woocommerce Integration | Cross-Site Request Forgery (CSRF) and Broken Access Control (BAC) |
LSD Google Maps Embedder | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
MachForm Shortcode | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
MailUp Auto Subscription | Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS) |
Marquee Style RSS News Ticker | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Mass Custom Fields Manager | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
MD Custom content after or before of post | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
MDC YouTube Download (BAC)er | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
MemeOne | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
MercadoLibre Integration | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
MFPlugin | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
MHR-Custom-Anti-Copy | Cross-Site Request Forgery (CSRF) and Cross-Site Request Forgery (CSRF) |
Modal Window | Cross-Site Request Forgery (CSRF) and Settings Change (BAC) |
More Link Modifier | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
MyAnime Widget | Cross-Site Request Forgery (CSRF) and Privilege Escalation (BAC) |
mybb Last Topics | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
MyBookTable Bookstore | Cross-Site Request Forgery (CSRF) |
my-related-posts | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
NAVER Analytics | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
News Publisher Autopilot | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Norse Rune Oracle Plugin | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Notify Odoo | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
NV Slider | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
OrangeBox | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Password Protect Plugin for WordPress | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
PayForm | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
PixelYourSite – Your smart PIXEL (TAG) Manager | Cross-Site Request Forgery (CSRF) |
Popup Box | Cross-Site Request Forgery (CSRF) |
Post Carousel Slider | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Post & Page Notes | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Post Title (TypeWriter) | Cross-Site Request Forgery (CSRF) and Privilege Escalation (BAC) |
PPO Call and Actions | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Prayer Times Anywhere | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Pretty Url | Cross-Site Request Forgery (CSRF) |
Quote Tweet | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Radius Blocks | Cross-Site Request Forgery (CSRF) |
Really Simple SSL | Cross-Site Request Forgery (CSRF) |
Real Seguro Viagem | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Rename Author Slug | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
ReviewsTap | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Rocket Media Library Mime Type | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Roi Calculator | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
root Cookie | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Royal Elementor Addons | Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS) |
RSS News Scroller | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
RSV GMaps | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Scratch & Win – Giveaways and Contests | Cross-Site Request Forgery (CSRF)via Reset (BAC)_installation Function |
Scroll Styler | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Secure CAPTCHA | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Send and Twitter | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
SEOReseller Partner | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Shabbos and Yom Tov | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
ShipWorks Connector for Woocommerce | Cross-Site Request Forgery (CSRF) to Service Password/Username Update (BAC) |
Shockingly Big IE6 Warning | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Shortcode in Comment | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Side Menu Lite | Cross-Site Request Forgery (CSRF) and Settings Change (BAC) |
Simple Add Pages or Posts | Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS) |
Simple Project Manager | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
SingSong | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Slider for Writers | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Smart Agenda | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Smoothness Slider Shortcode | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Snippy | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Social Analytics | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Starter Templates | Cross-Site Request Forgery (CSRF) |
Sticky Buttons | Cross-Site Request Forgery (CSRF) and Settings Change (BAC) |
Stop Comment Spam | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Strx Magic Floating Sidebar Maker | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Style Admin | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Subscription DNA | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Target Video Easy Publish | Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS) |
Taxonomy/Term and Role based Discounts for WooCommerce | Cross-Site Request Forgery (CSRF) and Settings Change (BAC) |
Theme My Ontraport Smartform | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
ThePerfectWedding.nl Widget | Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS) |
TH Variation Swatches | Cross-Site Request Forgery (CSRF) to Plugin Settings Reset (BAC) |
Title Experiments Free | Cross-Site Request Forgery (CSRF) |
Tock Widget | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Transporters.io | Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS) |
TubePress.NET | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Twitter Post | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Twitter Shortcode | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Ultimate Coming Soon & Maintenance | Cross-Site Request Forgery (CSRF) |
Ultimate Coming Soon & Maintenance | Cross-Site Request Forgery (CSRF) |
Ultimate Subscribe | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Universal Analytics Injector | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
UpDownUpDown | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Uptime Robot | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
ViewMedica 9 | Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS) |
ViewMedica 9 | Cross-Site Request Forgery (CSRF) to SQL Injection (SQLi) |
VikAppointments Services Booking Calendar | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
VikBooking Hotel Booking Engine & PMS | Cross-Site Request Forgery (CSRF) to File Upload (BAC) |
Virtual Bot | Cross-Site Request Forgery (CSRF) Cross-Site Scripting (XSS) |
Visit Site Link enhanced | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
W3SPEEDSTER | Cross-Site Request Forgery (CSRF) |
Webcamconsult | Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS) |
Web Push | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Web Testimonials | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Wizhi Multi Filters by Wenprise | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Wonder FontAwesome | Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS) |
Woocommerce check pincode/zipcode for shipping | Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS) |
WooCommerce Cloak Affiliate Links | Cross-Site Request Forgery (CSRF) |
Word Freshener | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
WordPress Data Guard | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
WordPress Gallery Plugin | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
WordPress Logging Service | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
WP Background Tile | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
WP-BibTeX | Cross-Site Request Forgery (CSRF) to and Cross-Site Scripting (XSS) |
WP-BlackCheck | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
WP Cookies Alert | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
WP Customer Area | Event Log Deletion (BAC) from Cross-Site Request Forgery (CSRF) |
WP Custom Google Search | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
WP Fast Total Search | Cross-Site Request Forgery (CSRF) |
WP-FB-AutoConnect | Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS) |
WP Go Maps | Cross-Site Request Forgery (CSRF) |
wp-greet | Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS) |
WP Image Upload (BAC)er | Cross-Site Request Forgery (CSRF) to File Deletion (BAC) |
WP Lyrics | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
WP Options Editor | Cross-Site Request Forgery (CSRF) and Privilege Escalation (BAC) |
WP Panoramio | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Wp-Scribd-List | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
WP Service Payment Form With Authorize.net | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
WP Simple Sitemap | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
wpSOL | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
WP SpaceContent | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
WP User Profile Avatar | Cross-Site Request Forgery (CSRF) to Settings Update (BAC) |
WP VTiger Synchronization | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
Zephyr Admin Theme | Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) |
WordPress CSRF & Cross-Site Request Forgery reported in 2023: | 949 |
WordPress CSRF & Cross-Site Request Forgery reported in 2024: | 876 |
WordPress CSRF & Cross-Site Request Forgery reported in 2025: | 328 |
WHO needs managed WP Maintenance? EVERYBODY!
Today’s reality requires daily clean-ups with database optimisations, weekly updates and upgrades for both free & premium modules, plus the occasional emergency changes when critical vulnerabilities are publicly disclosed without patches. Order WP Cross-Site Request Forgery Patch Management.
Security is not a single-task job
Need managed WP Security and got no clue where to start? Hire an expert. Pay a coffee per week, its cheaper than 1 hour for a freelancer.