VYPR
Medium severity5.4NVD Advisory· Published Feb 24, 2025· Updated Apr 23, 2026

CVE-2025-27340

CVE-2025-27340

Description

Cross-Site Request Forgery (CSRF) vulnerability in Forge12 Interactive GmbH F12-Profiler f12-profiler allows Cross Site Request Forgery.This issue affects F12-Profiler: from n/a through <= 1.3.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-Site Request Forgery in WordPress F12-Profiler plugin up to v1.3.9 allows attackers to force privileged users to perform unwanted actions.

Vulnerability

Overview CVE-2025-27340 is a Cross-Site Request Forgery (CSRF) vulnerability in the F12-Profiler plugin for WordPress, affecting all versions up to and including 1.3.9 [1]. The plugin fails to implement proper CSRF tokens or validation mechanisms on state-changing requests, allowing attackers to forge requests on behalf of authenticated users.

Exploitation

To exploit this vulnerability, an attacker must trick a privileged user (such as an administrator) into performing an action like clicking a malicious link or visiting a crafted web page [1]. No direct network access is required, but the victim must be logged into the WordPress site. The attacker can craft requests that, when triggered, perform actions under the victim's authentication.

Impact

Successful exploitation allows an attacker to force the victim to execute unwanted actions within the plugin, such as modifying settings, deleting profiles, or other unauthorized operations [1]. The CVSS score of 5.4 reflects a medium severity, and while user interaction is required, the potential for abuse in mass-exploit campaigns is noted by Patchstack.

Mitigation

The vulnerability is patched in version 1.4.0 of the plugin. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for the plugin to ensure protection [1]. If unable to update, consider disabling the plugin or implementing additional CSRF protections.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.