CVE 4.3 MEDIUM

Popover Windows <= 1.2 - Cross-Site Request Forgery to Arbitrary Popover Configuration Update_CVE-2025-14394

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Description

The Popover Windows plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Basic Information

ID CVE-2025-14394
Source Wordfence
Published Dec 13, 2025 at 04:31

Affected Product

Vendor melodicmedia
Product Popover Windows
Version *
Affected Versions melodicmedia Popover Windows *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.