CVE-2025-4654

LOW

Soumettre.fr < 2.1.5 - Unauthenticated Data Modification via make_signature Function

Title source: llm
STIX 2.1

Description

The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper authorization checks on the make_signature function in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to create/edit/delete Soumettre posts. This vulnerability affects only installations where the soumettre account is not connected (i.e. API key is not installed)

Scores

CVSS v3 3.7
EPSS 0.0023
EPSS Percentile 13.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285
Status published
Products (1)
soumettre/Soumettre.fr < 2.1.5
Published Jul 02, 2025
Tracked Since Feb 18, 2026