VYPR
Medium severity4.3NVD Advisory· Published May 19, 2025· Updated Apr 23, 2026

CVE-2025-39375

CVE-2025-39375

Description

Cross-Site Request Forgery (CSRF) vulnerability in Ashok G Easy Child Theme Creator easy-child-theme-creator allows Cross Site Request Forgery.This issue affects Easy Child Theme Creator: from n/a through <= 1.3.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF vulnerability in Easy Child Theme Creator plugin up to 1.3.1 allows attackers to force privileged users to execute unwanted actions.

The Easy Child Theme Creator plugin for WordPress versions up to and including 1.3.1 contains a Cross-Site Request Forgery (CSRF) vulnerability. This security flaw allows an attacker to trick a privileged user into unknowingly executing malicious actions, as the plugin fails to properly validate or enforce anti-CSRF tokens on sensitive requests [1].

Exploitation requires user interaction, such as clicking a malicious link or visiting a crafted page while authenticated. The attacker does not need special privileges but must convince a higher-privileged user (e.g., administrator) to perform an action. This attack vector is commonly used in mass-exploit campaigns targeting multiple websites [1].

Successful exploitation enables an attacker to perform unauthorized actions under the victim's authentication, such as modifying settings or creating malicious child themes. The CVSS score of 4.3 (Medium) reflects the requirement for user interaction and the potential impact on integrity [1].

As of the publication date, the vendor has not released a patched version. Users are strongly advised to update the plugin once a fix becomes available or to disable it until then. Immediate action is recommended due to the risk of mass exploitation [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.