CVE Details
Basic Information
| Title | CVE-2025-48340 |
|---|---|
| Type | cve |
| Published | 2025-05-19T21:15:22 |
| Last Seen | 2025-05-19T21:24:03 |
CVSS Information
| Base Score | 9.8 (CRITICAL) |
|---|---|
| Attack Vector | NETWORK |
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AI Analysis
| AI Description | A critical Cross-Site Request Forgery (CSRF) vulnerability in the Danny Vink User Profile Meta Manager WordPress plugin allows attackers to perform privilege escalation. This could enable unauthorized actions, such as taking over user accounts or gaining elevated privileges, posing a significant security risk. |
|---|---|
| AI Severity | Critical |
| Vendor | WordPress Community |
| Product | Danny Vink User Profile Meta Manager |
| Affected Version | Not specified |
Additional Information
| CVE List | CVE-2025-48340 |
|---|---|
| CWE List | CWE-352 |
| Bulletin Family | cve |
Description
Cross-Site Request Forgery (CSRF) vulnerability in Danny Vink User Profile Meta Manager allows Privilege Escalation. This issue affects User…
CVSS Score Summary
Base Score: %!f(string=#) (CRITICAL)