VYPR
Medium severity4.3NVD Advisory· Published May 7, 2025· Updated Apr 23, 2026

CVE-2025-47590

CVE-2025-47590

Description

Cross-Site Request Forgery (CSRF) vulnerability in JExtensions Store WPSpeed wpspeed allows Cross Site Request Forgery.This issue affects WPSpeed: from n/a through <= 2.6.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF vulnerability in WPSpeed plugin versions up to 2.6.5 allows attackers to force privileged users to execute unwanted actions.

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WPSpeed plugin for WordPress, affecting all versions up to and including 2.6.5 [1]. The flaw stems from insufficient CSRF protections, enabling attackers to craft malicious requests that appear legitimate to the server. When a privileged user interacts with a crafted link or page, the attacker can force the execution of unintended actions under the victim's authentication [1].

Exploitation requires user interaction—a logged-in administrator or other privileged user must click a malicious link or visit a specially crafted page. This threat is leveraged in mass-exploit campaigns targeting thousands of websites, regardless of their traffic or popularity [1]. The attack surface is broad because the plugin lacks proper nonce or token validation for sensitive operations.

If successfully exploited, an attacker could make unauthorized changes to the WordPress site, such as modifying plugin settings, injecting malicious code, or altering user roles, all under the authority of the victim user. The CVSS v3 base score of 4.3 (Medium) reflects the need for user interaction and the partial impact on integrity [1].

The vulnerability has been addressed in version 2.6.6. Users are strongly advised to update immediately; Patchstack users can enable auto-updates for vulnerable plugins. For those unable to update, a hosting provider or web developer should be consulted to apply temporary mitigations [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.