CVE · Medium

CVE-2025-49273 — WP Tools Debug Log, Repair, Javascript errors, Jquery errors, Increase Maximum Limits, File Permissions, Transients, Error Log [wptools] < 5.25 (closed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-49273 WP Tools Debug Log, Repair, Javascript errors, Jquery errors, Increase Maximum Limits, File Permissions, Transients, Error Log [wptools] < 5.25 (closed) Cross-Site Request Forgery (CSRF) Medium 4.3 < 5.25 5.25 2025-06-05

CVE-2025-49273

The WP Tools Repair plugin for WordPress has a security flaw that affects all versions up to 5.24, allowing malicious individuals to deceive administrators into executing unintended actions by exploiting a weakness in the validation process of certain functions. This vulnerability stems from inadequate or misconfigured checks for a specific type of security token. As a result, an attacker can manipulate a site's administrator into performing unauthorized tasks simply by tricking them into clicking on a link.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.