CVE-2025-2797
EUVD-2025-968304.04.2025, 07:15
The Woffice Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.4.21. This is due to missing or incorrect nonce validation on the 'woffice_handle_user_approval_actions' function. This makes it possible for unauthenticated attackers to approve registration for any user via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| xtendify | woffice | 𝑥 < 5.4.22 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration