PT-2025-30389 · WordPress · Latest Post Accordian Slider

Johannes Skamletz

+1

·

Published

2025-07-22

·

Updated

2025-07-22

·

CVE-2025-7687

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Latest Post Accordian Slider plugin for WordPress versions prior to 1.4
Description The Latest Post Accordian Slider plugin for WordPress is susceptible to Cross-Site Request Forgery due to missing or incorrect nonce validation on the lpaccordian page. This allows unauthenticated attackers to update settings and inject malicious web scripts via a forged request if they can trick a site administrator into performing an action, such as clicking a link.
Recommendations Update the Latest Post Accordian Slider plugin to version 1.4 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-7687

Affected Products

Latest Post Accordian Slider