CVE-2025-47661
Description
Cross-Site Request Forgery (CSRF) vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows Cross Site Request Forgery.This issue affects 워드프레스 결제 심플페이: from n/a through <= 5.2.11.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cross-Site Request Forgery (CSRF) vulnerability in the WordPress pgall-for-woocommerce plugin allows attackers to force privileged users to execute unwanted actions; fixed in version 5.3.3.
The vulnerability is a Cross-Site Request Forgery (CSRF) in the WordPress plugin 'pgall-for-woocommerce' (워드프레스 결제 심플페이), affecting versions up to and including 5.2.11. The root cause is a missing or insufficient CSRF token validation, which allows an attacker to craft malicious requests that are executed in the context of an authenticated administrator.
Exploitation requires user interaction: a privileged user (such as an admin) must be tricked into clicking a malicious link, visiting a crafted page, or submitting a form while logged into the WordPress site. No direct authentication is needed for the attacker, but the victim must have an active session with sufficient privileges.
Successful exploitation could allow an attacker to perform unauthorized actions on behalf of the victim, such as modifying plugin settings, changing payment configurations, or initiating transactions. The CVSS score of 5.4 (Medium) reflects the need for user interaction and the potential for limited impact, though the vulnerability could be chained in broader attacks.
The vendor has released version 5.3.3 to address the issue. Users are strongly advised to update immediately. Patchstack recommends enabling auto-updates for vulnerable plugins. No workarounds are mentioned, so updating is the only reliable mitigation [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.