PT-2025-41680 · WordPress · Widgetpack Comment System

Claw.K

+1

·

Published

2025-10-11

·

Updated

2025-10-11

·

CVE-2025-9621

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WidgetPack Comment System versions prior to 1.6.2
Description The software is susceptible to Cross-Site Request Forgery due to missing or incorrect nonce validation on the wpcmt sync action within the wpcmt request handler function. This allows unauthenticated attackers to trigger comment synchronization events through a forged request if they can trick a site administrator into performing an action, such as clicking a link.
Recommendations Update WidgetPack Comment System to version 1.6.2 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-9621

Affected Products

Widgetpack Comment System