PT-2025-13508 · WordPress · Wp Database Optimizer

Nabil Irawan

·

Published

2025-03-28

·

Updated

2025-03-28

·

CVE-2025-31474

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Database Optimizer versions 1.2.1.3 and earlier
Description A Cross-Site Request Forgery (CSRF) issue allows unauthorized actions to be performed on behalf of a user. This can lead to various security problems, as an attacker could potentially manipulate user interactions with the application.
Recommendations For WP Database Optimizer versions 1.2.1.3 and earlier, consider implementing proper CSRF token validation to prevent unauthorized requests. As a temporary workaround, restrict access to sensitive functionality that may be exploited through CSRF attacks until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-31474

Affected Products

Wp Database Optimizer