CVE-2025-47667
Description
Cross-Site Request Forgery (CSRF) vulnerability in qusupport LiveAgent liveagent allows Cross Site Request Forgery.This issue affects LiveAgent: from n/a through <= 4.4.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cross-Site Request Forgery (CSRF) vulnerability in WordPress LiveAgent plugin versions up to 4.4.7 allows attackers to force privileged users to execute unwanted actions.
Vulnerability
Overview
The LiveAgent plugin for WordPress, versions 4.4.7 and earlier, contains a Cross-Site Request Forgery (CSRF) vulnerability. This flaw arises from insufficient validation of request origins, enabling an attacker to trick a logged-in administrator or other privileged user into performing unintended actions [1].
Exploitation
Details
Exploitation requires user interaction: the victim must click a malicious link, visit a crafted page, or submit a form while authenticated. The attacker does not need direct access to the site but can leverage social engineering to deliver the payload. The vulnerability is noted to be used in mass-exploit campaigns targeting thousands of websites [1].
Impact
Successful exploitation allows an attacker to force the victim to execute actions under their current session, such as changing settings, creating new admin accounts, or modifying content. The CVSS v3 score is 5.4 (Medium), reflecting the need for user interaction and the potential for privilege escalation [1].
Mitigation
The vendor has released version 4.4.8 which resolves the CSRF issue. Users are strongly advised to update immediately. For those unable to update, consulting a hosting provider or web developer is recommended. Patchstack users can enable auto-updates for the plugin [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.