
CSRF Vulnerability Discovered in WordPress Plugin Custom CSS, JS & PHP
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been discovered in the WordPress plugin Custom CSS, JS & PHP. This vulnerability, identified as CVE-2025-39601, allows an attacker to inject malicious PHP code through unauthorized POST requests, leading to remote code execution (RCE). This vulnerability affects users of the WPFactory Custom CSS, JS & PHP plugin, enabling attackers to compromise targeted systems.