VYPR
Medium severity4.3NVD Advisory· Published Jun 20, 2025· Updated Apr 23, 2026

CVE-2025-49972

CVE-2025-49972

Description

Cross-Site Request Forgery (CSRF) vulnerability in David Wood TM Replace Howdy tm-replace-howdy allows Cross Site Request Forgery.This issue affects TM Replace Howdy: from n/a through <= 1.4.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

TM Replace Howdy WordPress plugin <=1.4.2 is vulnerable to CSRF, enabling attackers to force authenticated users to execute unintended actions.

Vulnerability

Overview The TM Replace Howdy plugin for WordPress, versions up to and including 1.4.2, contains a Cross-Site Request Forgery (CSRF) vulnerability. This issue arises from a lack of proper verification of the origin of requests, allowing a malicious actor to craft requests that, when triggered by an authenticated user, perform unwanted actions under that user's session [1].

Exploitation

Vector Exploitation requires user interaction; an attacker must trick a privileged user (such as an administrator) into clicking a malicious link, visiting a crafted page, or submitting a form while authenticated to the WordPress site. No additional privileges are needed beyond the victim's existing session [1].

Impact

Successful exploitation could allow an attacker to force the victim to execute unintended actions under their current authentication. While the specific actions depend on the plugin's capabilities, CSRF in this context could lead to settings changes or other unauthorized operations [1].

Mitigation

The vulnerability is patched in newer versions of the plugin; users are strongly advised to update TM Replace Howdy immediately. If updating is not possible, consulting a hosting provider or web developer for temporary workarounds is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.