CVE-2025-12028 | IndieAuth Plugin up to 4.5.4 on WordPress wp-login.php?action=indieauth login_form_indieauth cross-site request forgery
A vulnerability, which was classified as problematic, has been found in IndieAuth Plugin up to 4.5.4 on WordPress. This issue affects the function login_form_indieauth of the file /wp-login.php?action=indieauth. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-12028. It is possible to initiate the attack remotely. There is no exploit available.