VYPR
Medium severity4.3NVD Advisory· Published Aug 28, 2025· Updated Apr 23, 2026

CVE-2025-48363

CVE-2025-48363

Description

Cross-Site Request Forgery (CSRF) vulnerability in Metin Saraç Popup for CF7 with Sweet Alert cf7-sweet-alert-popup allows Cross Site Request Forgery.This issue affects Popup for CF7 with Sweet Alert: from n/a through <= 1.6.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A CSRF vulnerability in the Popup for CF7 with Sweet Alert WordPress plugin (≤1.6.5) allows attackers to trick privileged users into performing unintended actions.

The Popup for CF7 with Sweet Alert plugin for WordPress fails to implement proper Cross-Site Request Forgery (CSRF) protections. This means that requests to perform sensitive actions within the plugin are not validated against a unique token, making it possible for an attacker to forge requests on behalf of an authenticated administrator [1].

To exploit this vulnerability, an attacker must trick a logged-in user with sufficient privileges (such as an administrator) into clicking a malicious link or visiting a crafted page. The attacker does not need any authentication themselves, but the victim must perform an action like clicking a link or submitting a form. This user interaction is required for the attack to succeed [1].

If exploited, an attacker can force the victim's browser to execute unwanted actions under the victim's current session. This could include changing plugin settings, deleting data, or performing other administrative tasks without the victim's consent. The vulnerability is noted to be used in mass-exploit campaigns targeting thousands of websites [1].

As a mitigation, users should update the plugin to version 1.6.6 or later, which contains the fix. If updating is not immediately possible, it is recommended to contact the hosting provider or a web developer for assistance. No workaround is currently available [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.