Description
The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the foxtool_login_google() function. This makes it possible for unauthenticated attackers to establish an OAuth Connection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
* (semver)
Timeline
| 2025-12-11: | Disclosed |
Credits
D01EXPLOIT OFFICIAL
References
www.wordfence.com/...-f6a2-404c-9d0d-5fc3da6a896c?source=cve
plugins.svn.wordpress.org/foxtool/tags/2.5.2/inc/goo.php
wordpress.org/plugins/foxtool/
plugins.trac.wordpress.org/...0foxtool&sfp_email=&sfph_mail=
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.