WordPress · Mpwizard – Create Mercado Pago Payment Links · CVE-2025-9885
**Name of the Vulnerable Software and Affected Versions**
MPWizard – Create Mercado Pago Payment Links plugin for WordPress versions prior to 1.2.2
**Description**
The software is susceptible to Cross-Site Request Forgery, allowing unauthenticated attackers to delete arbitrary posts. This is possible due to missing or incorrect nonce validation in the `/includes/admin/class-mpwizard-table.php` file. An attacker can exploit this by tricking a site administrator into performing an action, such as clicking a malicious link, to execute a forged request.
**Recommendations**
Update the MPWizard – Create Mercado Pago Payment Links plugin for WordPress to version 1.2.2 or later.