CVE-2025-4654: Soumettre Soumettre.fr

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper authorization checks on the make_signature function in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to create/edit/delete Soumettre posts. This vulnerability affects only installations where the soumettre account is not connected (i.e. API key is not installed)

Affected products

  • Soumettre Soumettre.fr: up to and including 2.1.5

Published 2025-07-02. Last modified 2026-06-17.