PT-2025-50819 · Foxtheme+1 · Foxtool All-In-One: Contact Chat Button+1

·

CVE-2025-13408

·

Published

2025-12-11

·

Updated

2025-12-12

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress versions prior to 2.5.3
Description Cross-Site Request Forgery occurs due to missing or incorrect nonce validation in the foxtool login google() function. A nonce is a unique token used to prevent the replay of requests. This flaw allows unauthenticated attackers to establish an OAuth Connection through a forged request if a site administrator is tricked into clicking a malicious link.
Recommendations Update the plugin to a version newer than 2.5.2. As a temporary workaround, restrict access to the foxtool login google() function until the update is applied.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13408

Affected Products

Foxtool All-In-One: Contact Chat Button
Foxtool