PT-2025-30994 · WordPress · Memory Usage

·

CVE-2025-8104

·

Published

2025-07-27

·

Updated

2025-07-27

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Memory Usage plugin for WordPress versions prior to 3.99
Description The Memory Usage plugin for WordPress is susceptible to Cross-Site Request Forgery due to missing nonce validation in the wpmemory install plugin() function. This allows unauthenticated attackers to silently install whitelisted plugins via a forged request if they can trick a site administrator into performing an action.
Recommendations Update the Memory Usage plugin to version 3.99 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-8104

Affected Products

Memory Usage