
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12173 is a Cross-Site Request Forgery (CSRF) vulnerability in the WP Admin Microblog plugin for WordPress. It affects all versions up to and including 3.1.1, stemming from missing or incorrect nonce validation on the wp-admin-microblog page. The vulnerability was published on November 18, 2025, and assigned by Wordfence. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-352 (Cross-Site Request Forgery), arising from the absence of proper nonce validation on the plugin's wp-admin-microblog page. An unauthenticated attacker can craft a malicious HTTP request that, when triggered by a logged-in administrator (e.g., via a deceptive link or embedded form), causes the server to process the request as if it originated from the administrator. No authentication or elevated privileges are required on the attacker's side; only user interaction from the victim administrator is needed (Wordfence).
Successful exploitation allows an unauthenticated attacker to send microblog messages on behalf of a WordPress administrator, resulting in a low-integrity impact with no confidentiality or availability consequences. The scope is limited to the affected WordPress instance, and the attack does not enable code execution, data exfiltration, or lateral movement. The primary risk is unauthorized content posting or potential misuse of the administrator's messaging capabilities within the WordPress admin panel (Wordfence, Red Hat CVE).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-12173. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering to trick an administrator into clicking a malicious link, which limits its practical exploitability (Wordfence).
wp-admin-microblog page endpoint, with the desired message payload and no valid nonce.wp-admin-microblog page from unexpected referrer origins or with missing/invalid nonce values.Users should update the WP Admin Microblog plugin to version 3.1.2 or later, which addresses the missing nonce validation (Wordfence). As a general precaution, administrators should avoid clicking unsolicited links while logged into the WordPress admin panel. If immediate patching is not possible, consider deactivating the plugin until the update can be applied.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."