CVE-2025-1320 - TeachPress WordPress Cross-Site Request Forgery (CSRF) Vulnerability

CVE ID : CVE-2025-1320 Published : March 25, 2025, 7:15 a.m. | 29 minutes ago Description : The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.0.9. This is due to missing or incorrect nonce validation on the import.php page. This makes it possible for unauthenticated attackers to delete imports via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Mär 25, 2025 - 08:45
 0  0
CVE-2025-1320 - TeachPress WordPress Cross-Site Request Forgery (CSRF) Vulnerability
CVE ID : CVE-2025-1320
Published : March 25, 2025, 7:15 a.m. | 29 minutes ago
Description : The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.0.9. This is due to missing or incorrect nonce validation on the import.php page. This makes it possible for unauthenticated attackers to delete imports via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...