PT-2026-20599 · WordPress · Page Title

Dayea Song

·

Published

2026-02-19

·

Updated

2026-02-19

·

CVE-2025-13438

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Page Title, Description & Open Graph Updater plugin for WordPress versions prior to 1.03
Description The plugin is susceptible to Cross-Site Request Forgery (CSRF) due to the absence of nonce validation on several AJAX actions, including dieno update page title. This allows attackers to update page titles and metadata by forging requests, provided they can trick a site administrator into performing an action, such as clicking a link.
Recommendations Update the Page Title, Description & Open Graph Updater plugin to version 1.03 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-13438

Affected Products

Page Title