Custom Post Type WordPress Plugin Cross-Site Request Forgery Vulnerability
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Custom Post Type plugin for WordPress, affecting all versions through 1.0. The vulnerability arises from inadequate nonce validation in the custom post type deletion process. This flaw allows unauthenticated attackers to delete custom post types by sending a forged request, provided they can persuade a site administrator to click a link or perform a similar action.
Impact
Exploitation of this vulnerability could lead to unauthorized deletion of custom post types by an attacker.
Added: Nov 21, 2025, 8:23 AM
Updated: Nov 21, 2025, 3:56 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
7.0remediation
0.0relevance
1.1threat
3.2urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
