CVE-2025-47614
Description
Cross-Site Request Forgery (CSRF) vulnerability in Chris Clark LessButtons Social Sharing and Statistics lessbuttons allows Cross Site Request Forgery.This issue affects LessButtons Social Sharing and Statistics: from n/a through <= 1.6.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CSRF vulnerability in the LessButtons Social Sharing and Statistics WordPress plugin up to version 1.6.1 allows an attacker to change plugin settings by tricking a privileged user into an unwanted action.
The LessButtons Social Sharing and Statistics plugin for WordPress (versions <= 1.6.1) contains a Cross-Site Request Forgery (CSRF) vulnerability. The plugin fails to validate or verify the origin of requests when processing settings changes, allowing a malicious actor to craft a request that modifies plugin configuration on behalf of an authenticated administrator [1].
Exploitation requires user interaction: a privileged user must be tricked into clicking a malicious link, visiting a crafted page, or submitting a form while authenticated to the WordPress admin. No other authentication or network access is needed beyond the victim user's session [1].
Successful exploitation could allow an attacker to change plugin settings without authorization. While the impact is limited to configuration changes, such CSRF flaws are often chained with other vulnerabilities or used in mass-exploit campaigns targeting thousands of WordPress sites [1].
The vendor has not released a patch; however, users are advised to update the plugin to a fixed version if available, or contact their hosting provider for assistance as an immediate mitigation. This vulnerability is not yet listed on CISA's Known Exploited Vulnerabilities (KEV) catalog [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.