PT-2025-38918 · WordPress · Yonisink Custom Post Type Images

Mika

·

Published

2025-09-22

·

Updated

2025-09-23

·

CVE-2025-58255

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions yonisink Custom Post Type Images versions through 0.5
Description A Cross-Site Request Forgery (CSRF) issue exists in yonisink Custom Post Type Images that can lead to Code Injection. The issue allows for potential code execution through crafted requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-58255

Affected Products

Yonisink Custom Post Type Images