CVE-2025-23797 CRITICAL

CVE-2025-23797: WordPress WP Options Editor plugin <= 1.1 - CSRF to Privilege Escalation vulnerability

Vendor Mike Selander
Product WP Options Editor
Weakness CWE-352 · CSRF
Published January 16, 2025
Last update May 11, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Cross-Site Request Forgery (CSRF) vulnerability in Mike Selander WP Options Editor wp-options-editor allows Privilege Escalation.This issue affects WP Options Editor: from n/a through <= 1.1.

Explanation of Vulnerability in Simple Terms

02Summary

WP Options Editor versions 1.1 and earlier contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform unauthorized actions on a WordPress site without the site owner's knowledge. An attacker can craft a malicious link or page that, when visited by a logged-in administrator, modifies WordPress options or settings. No special privileges or user interaction beyond visiting a page are required to exploit this flaw.

What an attacker can do

03Attacker Capabilities

Modify WordPress site options and settings by tricking an admin into visiting a malicious page.

Potential impact on your site

04Site Impact

An attacker can change critical WordPress settings (site URL, admin email, etc.) without your permission if you visit a malicious link while logged in.

Conditions required to exploit

05Prerequisites

The site must run WP Options Editor 1.1 or earlier; the attacker needs a logged-in admin to visit their malicious link.

Key dates

06Disclosure timeline

January 16, 2025 CVE published
May 11, 2026 Record updated

Related vulnerabilities

08Related CVE