CVE-2025-10684 | Construction Light Plugin up to 1.6.7 on WordPress cross-site request forgery
A vulnerability classified as problematic has been found in Construction Light Plugin up to 1.6.7 on WordPress. The affected element is an unknown function. Performing manipulation results in cross-site request forgery.
This vulnerability is identified as CVE-2025-10684. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.