Foxtheme · Foxtool All-In-One: Contact Chat Button · CVE-2025-13408
**Name of the Vulnerable Software and Affected Versions**
Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress versions prior to 2.5.3
**Description**
Cross-Site Request Forgery occurs due to missing or incorrect nonce validation in the `foxtool login google()` function. A nonce is a unique token used to prevent the replay of requests. This flaw allows unauthenticated attackers to establish an OAuth Connection through a forged request if a site administrator is tricked into clicking a malicious link.
**Recommendations**
Update the plugin to a version newer than 2.5.2.
As a temporary workaround, restrict access to the `foxtool login google()` function until the update is applied.