| CVE ID | CVE-2025-4337 |
|---|---|
| Type | Cross-Site Request Forgery (CSRF) |
| Affected Component | WordPress Plugin AHAthat |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
| CVSS Score | 4.3 β Medium |
| Discovered by | Seckhmet |
A Cross-Site Request Forgery (CSRF) vulnerability was identified in the WordPress plugin AHAthat. This flaw allows an unauthenticated attacker to trigger unauthorized actions on behalf of a legitimate user, by tricking them into visiting a malicious page or clicking a crafted link.
The attack vector is network (AV:N), requires no privileges (PR:N) but needs user interaction (UI:R). Impact is limited to integrity (I:L) with no effect on confidentiality or availability.
Update the AHAthat plugin to the patched version as soon as available. In the meantime, disable the plugin or restrict access to the affected features. Implement CSRF tokens on all sensitive actions on the developer side.