CVE-2025-30981: WordPress WP-Recall plugin <= 16.26.14 - CSRF to Privilege Escalation vulnerability

6.3 CVSS

Description

Cross-Site Request Forgery (CSRF) vulnerability in tggfref WP-Recall allows Privilege Escalation. This issue affects WP-Recall: from n/a through 16.26.14.

Classification

CVE ID: CVE-2025-30981

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.3

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Problem Types

CWE-352 Cross-Site Request Forgery (CSRF)

Affected Products

Vendor: tggfref

Product: WP-Recall

References

https://nvd.nist.gov/vuln/detail/CVE-2025-30981
https://patchstack.com/database/wordpress/plugin/wp-recall/vulnerability/wordpress-wp-recall-plugin-16-26-14-csrf-to-privilege-escalation-vulnerability?_s_id=cve

Timeline