CVE · Medium

CVE-2025-53262 — Writesonic [writesonic] < 1.0.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-53262 Writesonic [writesonic] < 1.0.6 Cross-Site Request Forgery (CSRF) Medium 5.4 < 1.0.6 1.0.6 2025-06-27

CVE-2025-53262

The Writesonic plugin for WordPress contains a security weakness that allows malicious individuals to deceive administrators into executing unintended actions by exploiting the lack of proper validation checks in certain functions, thereby bypassing authentication requirements and potentially leading to unauthorized changes. This vulnerability affects all versions up to 1.0.5. An attacker could manipulate an administrator into clicking on a link or performing another action, allowing them to carry out unauthorized tasks.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.