CVE-2025-4654: Soumettre Soumettre.fr
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper authorization checks on the make_signature function in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to create/edit/delete Soumettre posts. This vulnerability affects only installations where the soumettre account is not connected (i.e. API key is not installed)
Affected products
- Soumettre Soumettre.fr: up to and including 2.1.5
Published 2025-07-02. Last modified 2026-06-17.