VYPR
Medium severity4.3NVD Advisory· Published Jun 20, 2025· Updated Apr 23, 2026

CVE-2025-49967

CVE-2025-49967

Description

Cross-Site Request Forgery (CSRF) vulnerability in marcusjansen Live Sports Streamthunder live-sports-streamthunder allows Cross Site Request Forgery.This issue affects Live Sports Streamthunder: from n/a through <= 2.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A CSRF vulnerability in the Live Sports Streamthunder WordPress plugin allows attackers to force privileged users into executing unintended actions.

Vulnerability

Overview

The Live Sports Streamthunder WordPress plugin (versions up to and including 2.1) contains a Cross-Site Request Forgery (CSRF) vulnerability [1]. This security flaw exists because the plugin fails to implement proper nonce or token validation on state-changing requests, allowing an attacker to craft malicious requests that appear legitimate to the server [1].

Exploitation

Details

To exploit this vulnerability, an attacker must trick a privileged user (such as an administrator) into clicking a malicious link, visiting a crafted page, or submitting a specially designed form while that user is authenticated to the WordPress site [1]. No additional privileges are required for the attacker beyond the ability to deliver the crafted request to the target user. This attack vector is commonly used in mass-exploit campaigns targeting thousands of websites simultaneously [1].

Impact

Successful exploitation enables an attacker to force the authenticated privileged user to perform unintended actions under their current session [1]. This could include changing plugin settings, modifying content, creating new administrative accounts, or other actions the victim user is authorized to perform. The CVSS v3 base score is 4.3 (Medium), reflecting the need for user interaction and the potential for significant but limited-impact actions [1].

Mitigation

As an immediate action, users should update the Live Sports Streamthunder plugin to a version newer than 2.1, which presumably contains a fix for this CSRF issue [1]. For those unable to update promptly, it is recommended to contact the hosting provider or a web developer for assistance [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.