CVE-2025-12061HIGH 8.6EPSS p4.7%
CVE-2025-12061CVE-2025-12061
Description
The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users to import and execute arbitrary SQL statements
Scoring
| CVSS 3.1 | 8.6 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
| EPSS | 0.15% probability of exploitation · percentile 4.7% · 2026-06-18T12:00:27Z |
| Published | 2025-11-26 |
| Last modified | 2026-04-15 |
Underlying weaknesses· 2
References
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Cross-Site Request Forgery (CSRF)cwe-352 | 0% | live |
| Weakness | Missing Authorizationcwe-862 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.