Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS, JS & PHP allows Remote Code Inclusion. This issue affects Custom CSS, JS & PHP: from n/a through 2.4.1.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Apr 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS, JS & PHP allows Remote Code Inclusion. This issue affects Custom CSS, JS & PHP: from n/a through 2.4.1. | |
Title | WordPress Custom CSS, JS & PHP plugin <= 2.4.1 - CSRF to RCE vulnerability | |
Weaknesses | CWE-352 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Patchstack
Published: 2025-04-16T12:44:15.534Z
Updated: 2025-04-16T14:00:07.048Z
Reserved: 2025-04-16T06:27:02.093Z
Link: CVE-2025-39601

No data.

Status : Awaiting Analysis
Published: 2025-04-16T13:15:52.790
Modified: 2025-04-16T13:25:37.340
Link: CVE-2025-39601

No data.