8.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Description
The Inspiro theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. This is due to missing or incorrect nonce validation on the inspiro_install_plugin() function. This makes it possible for unauthenticated attackers to install plugins from the repository via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Basic Information
ID
CVE-2025-8592
Source
Wordfence
Published
Aug 21, 2025 at 05:28
Affected Product
Vendor
wpzoom
Product
Inspiro
Version
*
Affected Versions
wpzoom Inspiro *
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/20f461d1-aeb2-4913-804c-6a081e48765a
- themes.trac.wordpress.org /browser/inspiro/2.1.1/inc/admin/pluginInstaller/class-inspiro-plugin-installer.php
- research.cleantalk.org /cve-2025-8592/
- themes.trac.wordpress.org /ticket/228813
- themes.trac.wordpress.org /changeset