
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12403 is a Cross-Site Request Forgery (CSRF) vulnerability in the Associados Amazon Plugin ("brzon") for WordPress, affecting all versions up to and including 0.8. The flaw arises from missing or incorrect nonce validation in the brzon_admin_panel() function, enabling unauthenticated attackers to update plugin settings and inject malicious web scripts by tricking an authenticated administrator into clicking a crafted link. It was published on November 4, 2025, and carries a CVSS v3.1 base score of 6.1 (Medium), assigned by Wordfence (Wordfence, Red Hat CVE).
The root cause is classified as CWE-352 (Cross-Site Request Forgery), specifically the absence of proper nonce validation in the brzon_admin_panel() function (see source lines 568, 569, and 589 of brzon.php version 0.8). Because WordPress nonces are not verified before processing administrative form submissions, an attacker can craft a malicious HTML page or link that, when visited by a logged-in administrator, silently submits a forged request to update plugin settings or inject arbitrary JavaScript into the site. Exploitation requires no privileges on the target site but does require social engineering to induce an administrator to trigger the forged request (Wordfence, WordPress Plugin Source).
Successful exploitation allows an unauthenticated attacker to modify plugin settings and inject persistent malicious scripts (Stored XSS) into the WordPress site by leveraging an administrator's authenticated session. This can result in limited confidentiality and integrity impacts — such as session cookie theft, credential harvesting, or defacement — affecting site visitors who encounter the injected scripts. Availability is not directly impacted, but a compromised admin panel could facilitate further attacks against the site or its users (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-12403. The EPSS score is extremely low at 0.000120, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement to trick an administrator into clicking a malicious link, limiting opportunistic mass exploitation (Feedly, Wordfence).
/wp-content/plugins/brzon/ paths.brzon_admin_panel() settings, embedding a malicious JavaScript payload in a settings field./wp-admin/ or admin-ajax endpoints associated with the brzon plugin settings panel from unusual referrer URLs or external origins.wp_options table) for the brzon plugin, particularly entries containing <script> tags or encoded JavaScript.The primary remediation is to update or remove the Associados Amazon Plugin ("brzon") from affected WordPress installations, as version 0.8 is confirmed vulnerable and no patched version has been publicly announced at the time of disclosure. Site administrators should audit plugin settings in the wp_options table for any unexpected or malicious content injected via this vulnerability. As a general hardening measure, restrict access to the WordPress admin panel by IP allowlisting and ensure administrators are cautious about clicking unsolicited links while authenticated (Wordfence).
Wordfence reported this vulnerability as part of their weekly WordPress vulnerability report for November 3–9, 2025, noting it as part of routine plugin security monitoring. No significant broader media coverage, vendor statements beyond the Wordfence advisory, or notable researcher commentary has been identified for this low-severity plugin vulnerability (Wordfence Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."