PT-2025-34511 · WordPress · Restore Permanently Delete Post/Page Data

Nabil Irawan

·

Published

2025-08-23

·

Updated

2025-08-23

·

CVE-2025-7839

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Restore Permanently delete Post or Page Data plugin for WordPress version 1.0
Description: The Restore Permanently delete Post or Page Data plugin for WordPress is susceptible to Cross-Site Request Forgery due to missing or incorrect nonce validation on the rp dpo dpa ajax dp delete data() function. This allows unauthenticated attackers to delete data by forging requests, provided they can trick a site administrator into performing an action.
Recommendations: Update the Restore Permanently delete Post or Page Data plugin to a version beyond 1.0. Ensure nonce validation is implemented correctly in the rp dpo dpa ajax dp delete data() function.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-7839

Affected Products

Restore Permanently Delete Post/Page Data