WHAT ARE YOU LOOKING FOR?

Raleigh, NC

32°F
Scattered Clouds Humidity: 79%
Wind: 2.06 M/S

Over 70,000 WordPress Sites Compromised by Inspiro Theme Vulnerability

Over 70,000 WordPress Sites Compromised by Inspiro Theme Vulnerability

A serious vulnerability (CVE-2025-8592) has been found in the Inspiro WordPress theme, affecting over 70,000 sites. The flaw allows unauthenticated attackers to exploit a Cross-Site Request Forgery (CSRF) bug and install plugins without admin consent. 

Disclosed on August 20, 2025, the issue stems from missing nonce validation in the inspiro_install_plugin() function. Attackers can trick logged-in admins into clicking malicious links, hijacking their session to install unauthorized plugins. 

Rated 8.1 (High) on the CVSS scale, the bug requires no login and minimal user interaction, making it easy to exploit. Researcher Dmitrii Ignatyev flagged the threat, and Wordfence warned of its potential for serious site compromise. 

WPZoom patched the flaw in version 2.1.3. Users on earlier versions should update immediately. The incident highlights ongoing risks in third-party WordPress themes and the importance of timely patching and security monitoring. 

 

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Image

With Cybersecurity Insights, current news and event trends will be captured on cybersecurity, recent systems / cyber-attacks, artificial intelligence (AI), technology innovation happening around the world; to keep our viewers fast abreast with the current happening with technology, system security, and how its effect our lives and ecosystem. 

Please fill the required field.