PT-2025-50819 · Foxtheme+1 · Foxtool All-In-One: Contact Chat Button+1
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress versions prior to 2.5.3
Description
Cross-Site Request Forgery occurs due to missing or incorrect nonce validation in the
foxtool login google() function. A nonce is a unique token used to prevent the replay of requests. This flaw allows unauthenticated attackers to establish an OAuth Connection through a forged request if a site administrator is tricked into clicking a malicious link.Recommendations
Update the plugin to a version newer than 2.5.2.
As a temporary workaround, restrict access to the
foxtool login google() function until the update is applied.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Foxtool All-In-One: Contact Chat Button
Foxtool