CVE-2025-9544

The Doppler Forms WordPress plugin through 2.5.1 registers an AJAX action install_extension without verifying user capabilities or using a nonce. As a result, any authenticated user — including those with the Subscriber role — can install and activate additional Doppler Forms WordPress plugin through 2.5.1 (limited to those whitelisted by the main Doppler Forms WordPress plugin through 2.5.1).
Configurations

No configuration.

History

29 Oct 2025, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

29 Oct 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-29 06:15

Updated : 2025-10-30 15:03


NVD link : CVE-2025-9544

Mitre link : CVE-2025-9544

CVE.ORG link : CVE-2025-9544


JSON object : View

Products Affected

No product.

CWE

No CWE.