Medium 6.5
2025-09-26< 3.9.2
CVE-2025-60040
Minimum safe version
3.9.2
Update to 3.9.2 or later to address 7 fixable vulnerabilities
CVE-2025-60040
CVE-2024-27962
CVE-2021-4416
CVE-2021-4342
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
CSRF Bypass in Multiple Plugins
WordPress wp-mpdf plugin <= 3.5.1 - Cross-Site Request Forgery (CSRF) vulnerability