Izem · Run Log · CVE-2025-9627
**Name of the Vulnerable Software and Affected Versions**
Run Log plugin for WordPress versions prior to 1.7.11
**Description**
Cross-Site Request Forgery occurs due to missing or incorrect nonce validation in the `oirl plugin options()` function. A nonce is a unique token used to protect against forged requests. This allows unauthenticated attackers to modify plugin settings, such as distance units, pace display preferences, style themes, and display positions, by tricking a site administrator into clicking a malicious link.
**Recommendations**
Update the plugin to a version later than 1.7.10.
As a temporary mitigation, restrict administrative access to the plugin settings until the update is applied.