VYPR
Medium severity4.3NVD Advisory· Published Sep 22, 2025· Updated Apr 23, 2026

CVE-2025-58199

CVE-2025-58199

Description

Cross-Site Request Forgery (CSRF) vulnerability in Fastly Fastly fastly allows Cross Site Request Forgery.This issue affects Fastly: from n/a through <= 1.2.28.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-Site Request Forgery in WordPress Fastly plugin (≤1.2.28) allows attackers to force privileged users to execute unintended actions.

Vulnerability

Overview

Cross-Site Request Forgery (CSRF) vulnerability exists in the Fastly plugin for WordPress versions up to and including 1.2.28. The plugin fails to validate or verify the origin of requests, allowing an attacker to craft malicious requests that are executed by an authenticated administrator without their knowledge [1].

Exploitation

Requirements

Exploitation requires the victim (a privileged user) to be logged into the WordPress admin panel and to perform an action such as clicking a malicious link, visiting a crafted page, or submitting a form. No direct authentication is needed by the attacker, but the victim must have sufficient privileges to execute the desired action [1].

Impact

An attacker can trick a privileged user into performing unauthorized actions, such as changing settings or performing state-altering operations, under the victim's current session. This can lead to configuration changes or other unintended modifications to the site [1].

Mitigation

The vulnerability has been patched in version 1.2.29. Users are strongly advised to update to the latest version. Patchstack users can enable auto-updates for vulnerable plugins. While the CVSS score is 4.3 (Medium), the Patchstack advisory notes that this vulnerability is unlikely to be exploited on a large scale, but updating remains the recommended action [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.