CVE-2025-25137

Executive Summary

CVE-2025-25137 exposes a CSRF flaw in the Social Links plugin (versions ≤1.0.11), enabling attackers to forge authenticated requests and potentially alter user data or perform unauthorized actions. The vulnerability is not yet listed in CISA KEV. Affected installations should update to 1.0.12 or later.


Authoritative CVE Metadata - CVSS Base Score: 6.5 (MEDIUM) - Published: 2025-03-03T14:15:53.200 - Last Modified: 2026-08-18T22:16:48.527

Original Description: Cross-Site Request Forgery (CSRF) vulnerability in kareemsultan Social Links social-links allows Cross Site Request Forgery.

This issue affects Social Links: from n/a through 1.0.11.

"On every thorn, delightful wisdom grows, In every rill a sweet instruction flows."

— Edward Young
Source: NVD