CVE advisoryCRITICAL
CVE-2025-60156
AR For WordPress Plugin CSRF Vulnerability Allows Web Shell Upload.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A critical Cross-Site Request Forgery vulnerability exists in a WordPress plugin that could enable an attacker to upload a web shell to a web server if a user is tricked into triggering it. This could potentially lead to unauthorized code execution and compromise of the web server and its data. Uncertainty remains rega