CVE-2025-30981

WordPress WP-Recall plugin <= 16.26.14 - CSRF to Privilege Escalation vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in tggfref WP-Recall allows Privilege Escalation. This issue affects WP-Recall: from n/a through 16.26.14.


We have discovered 868 live websites that are affected by CVE-2025-30981.

Run a Free Instant Scan




Affected Software

Product  Wp Recall
Category Wordpress Plugins
Vulnerable Domains868 live websites (100% of Wp Recall install base)
Vulnerable Versions
  • from 0 through 16.26.14
Vulnerable Versions Count83 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Jun 6, 2025
  • Updated - Jun 6, 2025

Credits

  • 0xd4rk5id3 (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-30981
United States68 websites



Russia649 websites
Ukraine56 websites
Belarus29 websites
Germany15 websites
Kazakhstan14 websites
GB5 websites
Cyprus4 websites
France3 websites
United Arab Emirates2 websites

Website Distribution by TLD

Number of websites using CVE-2025-30981
.ru587 websites
.com73 websites
.info11 websites
.org10 websites
.net5 websites
.de2 websites
.eu2 websites
.pl2 websites
.ch1 websites
.co.uk1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-30981

Top websites that are affected by CVE-2025-30981. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.ru Russia***,***
*****.ru Russia***,***
*******.ru Russia***,***
**********.ru Russia***,***
***********.ru United States***,***
********.com Russia***,***
******.ru Russia***,***
****.ru Russia*,***,***
***********.ru Russia*,***,***
*********.by Belarus*,***,***
See full domain list

FAQ

CVE-2025-30981 is Cross-Site Request Forgery (CSRF) in Wp Recall
A total of 868 websites have been identified as vulnerable to CVE-2025-30981, based on global website indexing conducted by WebTechSurvey.
The Wp Recall is affected by the CVE-2025-30981 vulnerability.
Wp Recall versions up to and including 16.26.14 are vulnerable to CVE-2025-30981.