CVE-2025-47590
Description
Cross-Site Request Forgery (CSRF) vulnerability in JExtensions Store WPSpeed wpspeed allows Cross Site Request Forgery.This issue affects WPSpeed: from n/a through <= 2.6.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CSRF vulnerability in WPSpeed plugin versions up to 2.6.5 allows attackers to force privileged users to execute unwanted actions.
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WPSpeed plugin for WordPress, affecting all versions up to and including 2.6.5 [1]. The flaw stems from insufficient CSRF protections, enabling attackers to craft malicious requests that appear legitimate to the server. When a privileged user interacts with a crafted link or page, the attacker can force the execution of unintended actions under the victim's authentication [1].
Exploitation requires user interaction—a logged-in administrator or other privileged user must click a malicious link or visit a specially crafted page. This threat is leveraged in mass-exploit campaigns targeting thousands of websites, regardless of their traffic or popularity [1]. The attack surface is broad because the plugin lacks proper nonce or token validation for sensitive operations.
If successfully exploited, an attacker could make unauthorized changes to the WordPress site, such as modifying plugin settings, injecting malicious code, or altering user roles, all under the authority of the victim user. The CVSS v3 base score of 4.3 (Medium) reflects the need for user interaction and the partial impact on integrity [1].
The vulnerability has been addressed in version 2.6.6. Users are strongly advised to update immediately; Patchstack users can enable auto-updates for vulnerable plugins. For those unable to update, a hosting provider or web developer should be consulted to apply temporary mitigations [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.