CVE-2025-13408

Published
View on NVD ↗
CVSS v3
4.3
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the foxtool_login_google() function. This makes it possible for unauthenticated attackers to establish an OAuth Connection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

<p>Foxtool is a product developed based on the real needs of managing WordPress websites. After a period of development, Foxtool has become an indispensable plugin for website administrators.</p> <p>The plugin boasts notable features including:</p> <ul> <li>Website optimization</li> <li>Advanced security</li> <li>Management tools</li> <li>Customizable display</li> <li>Powerful media management</li> <li>Handy tools for Posts and Pages</li> <li>Mail application</li> <li>Woocommerce convenience</li> <li>User permissions</li> <li>Customizable WordPress login</li> <li>Integration with Google services</li> <li>Chat functionality</li> <li>Information management</li> </ul> <p>Additionally, there are many other useful features that help save time for users. All are optimized to ensure stable and fast performance for your WordPress website</p> <h3>From within WordPress</h3> <ol> <li>Visit &#8216;Plugins &gt; Add New&#8217;</li> <li>Search for &#8216;Foxtool&#8217;</li> <li>Activate &#8216;Foxtool&#8217; from your Plugins page.</li> </ol> <h3>Manually</h3> <ol> <li>Upload the &#8216;foxtool&#8217; folder to the &#8216;/wp-content/plugins/&#8217; directory</li> <li>Activate the &#8216;Foxtool&#8217; plugin through the &#8216;Plugins&#8217; menu in WordPress</li> <li>Go to &#8220;after activation&#8221; below.</li> </ol>
WordPress Plugin DirectoryWordPress Plugin Directory
52.7K