PT-2025-44918 · WordPress · Wp Global Screen Options

Nabil Irawan

·

Published

2025-11-04

·

Updated

2025-11-04

·

CVE-2025-12069

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Global Screen Options versions up to and including 0.2
Description The WP Global Screen Options plugin for WordPress is susceptible to Cross-Site Request Forgery. This is caused by a lack of nonce validation in the updatewpglobalscreenoptions action handler. An unauthenticated attacker can potentially modify global screen options for all users by crafting a malicious request and tricking an administrator into performing an action, such as clicking a link.
Recommendations Update WP Global Screen Options to a version newer than 0.2.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-12069

Affected Products

Wp Global Screen Options