
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-7685 is a Cross-Site Request Forgery (CSRF) vulnerability in the "Like & Share My Site" WordPress plugin, affecting all versions up to and including 0.2. Due to missing or incorrect nonce validation on the lsms_admin page, unauthenticated attackers can update plugin settings and inject malicious web scripts by tricking a site administrator into clicking a crafted link. The vulnerability was published on July 22, 2025, and carries a CVSS v3.1 base score of 6.1 (Medium) (Wordfence, Red Hat CVE).
The root cause is improper CSRF protection (CWE-352) — the plugin's lsms_admin page fails to validate WordPress nonces before processing form submissions, allowing state-changing requests to be forged. An attacker crafts a malicious HTML page or link that, when visited by a logged-in administrator, silently submits a forged POST request to the plugin's admin endpoint. This can result in arbitrary settings changes and stored cross-site scripting (XSS) via injected web scripts. The vulnerable code is visible in the plugin's source at the WordPress plugin repository (Wordfence, Plugin Source).
Successful exploitation allows an attacker to modify plugin settings and inject persistent malicious scripts into the WordPress site, potentially affecting all site visitors through stored XSS. The CVSS scope is "Changed," indicating that the impact extends beyond the plugin itself to the broader WordPress environment and end users' browsers. Confidentiality and integrity are both rated Low, with no direct availability impact; however, injected scripts could be used for session hijacking, credential theft, or further site compromise (Wordfence).
lsms_admin page endpoint with attacker-controlled settings values and an injected script payload.lsms_admin admin page from unusual referrers or external origins.wp_options table) for the like-share-my-site plugin containing script tags or encoded payloads.<script> tags or JavaScript event handlers in plugin-rendered output on the frontend that were not intentionally configured by the administrator.Site administrators should immediately deactivate and remove the "Like & Share My Site" plugin (versions ≤ 0.2) if no patched version is available from the plugin author. As a general WordPress hardening measure, ensure all plugins are kept up to date and consider using a Web Application Firewall (WAF) such as Wordfence to block CSRF-based attacks. Monitor the WordPress plugin repository for an updated release that implements proper nonce validation on the lsms_admin page (Wordfence).
Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for July 21–27, 2025, noting it in their threat intelligence database. No significant independent researcher commentary or broad media coverage has been identified beyond standard vulnerability aggregator listings (Wordfence Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."