CVE-2025-39601 Information

Description

Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS JS & PHP allows Remote Code Inclusion. This issue affects Custom CSS JS & PHP: from n/a through 2.4.1.

Reference

https://patchstack.com/database/wordpress/plugin/custom-css/vulnerability/wordpress-custom-css-js-php-plugin-2-4-1-csrf-to-rce-vulnerability?_s_id=cve

Share on: