CVE-2025-48340 CRITICAL

CVE-2025-48340: WordPress User Profile Meta Manager plugin <= 1.02 - CSRF to Privilege Escalation vulnerability

Vendor Danny Vink
Product User Profile Meta Manager
Weakness CWE-352 · CSRF
Published May 19, 2025
Last update April 28, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Cross-Site Request Forgery (CSRF) vulnerability in Danny Vink User Profile Meta Manager user-profile-meta allows Privilege Escalation.This issue affects User Profile Meta Manager: from n/a through <= 1.02.

Explanation of Vulnerability in Simple Terms

02Summary

User Profile Meta Manager versions 1.02 and earlier contain a cross-site request forgery (CSRF) vulnerability that allows unauthenticated attackers to perform unauthorized actions on affected sites without user interaction. An attacker can craft a malicious request that, when processed by the vulnerable plugin, modifies user profile data or other site settings. This vulnerability requires no special privileges or user interaction to exploit.

What an attacker can do

03Attacker Capabilities

Perform unauthorized actions on the site, such as modifying user profiles or settings, without authentication.

Potential impact on your site

04Site Impact

User profile data and site settings can be altered by remote attackers without your knowledge or consent.

Conditions required to exploit

05Prerequisites

The vulnerable plugin must be installed and active; no user authentication or interaction required.

Key dates

06Disclosure timeline

May 19, 2025 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE