CVE-2025-31915 MEDIUM

CVE-2025-31915: WordPress Pixel Form BuilderPlugin & Autoresponder plugin <= 1.0.3 - Cross Site Request Forgery (CSRF) vulnerability

Vendor Kamleshyadav
Product Pixel WordPress Form BuilderPlugin & Autoresponder
Weakness CWE-352 · CSRF
Published May 16, 2025
Last update April 28, 2026

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Cross-Site Request Forgery (CSRF) vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder pixel-formbuilder allows Cross Site Request Forgery.This issue affects Pixel WordPress Form BuilderPlugin & Autoresponder: from n/a through <= 1.0.3.

Explanation of Vulnerability in Simple Terms

02Summary

The Pixel WordPress Form Builder plugin through version 1.0.3 is vulnerable to cross-site request forgery (CSRF). An attacker can trick a logged-in site administrator into performing unintended actions, such as modifying form settings or creating malicious forms. The vulnerability requires the admin to visit a malicious webpage while authenticated to the WordPress site.

What an attacker can do

03Attacker Capabilities

Trick an authenticated admin into modifying forms or site settings without their knowledge.

Potential impact on your site

04Site Impact

An attacker could alter your forms, change autoresponder settings, or inject malicious content into form submissions.

Conditions required to exploit

05Prerequisites

Admin must be logged into WordPress and visit an attacker-controlled webpage.

Key dates

06Disclosure timeline

May 16, 2025 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE