CVE-2025-8592
The Inspiro theme for WordPress is vulnerable to Cross-Site Request

Publication date: 2025-08-21

Last updated on: 2025-08-22

Assigner: [email protected]

Description
The Inspiro theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. This is due to missing or incorrect nonce validation on the inspiro_install_plugin() function. This makes it possible for unauthenticated attackers to install plugins from the repository via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Affected Vendors & Products
Vendor Product Version
wordpresstheme inspiro 2.1.3
wordpresstheme inspiro 2.1.2
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?


How can this vulnerability impact me? :


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart
Meta Information
CVE Publication Date:
2025-08-21
CVE Last Modified Date:
2025-08-22
Report Generation Date:
2025-11-03
AI Powered Q&A Generation:
2025-08-21
EPSS Last Evaluated Date:
2025-09-10
NVD Report Link: