CVE-2025-58236
Description
Cross-Site Request Forgery (CSRF) vulnerability in Mayo Moriyama Force Update Translations force-update-translations allows Cross Site Request Forgery.This issue affects Force Update Translations: from n/a through <= 0.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CSRF vulnerability in WordPress Force Update Translations plugin (<=0.5) allows attackers to force privileged users to execute unwanted actions.
The Force Update Translations plugin for WordPress (versions 0.5 and earlier) contains a Cross-Site Request Forgery (CSRF) vulnerability. The plugin fails to implement proper CSRF tokens or validation on certain administrative actions, allowing an attacker to craft malicious requests that are executed under the authentication of a privileged user [1].
Exploitation requires user interaction: a privileged user (such as an administrator) must be tricked into clicking a malicious link, visiting a crafted page, or submitting a form while authenticated to the WordPress admin panel. The attack can be initiated remotely without any special privileges, but the victim must perform the action [1].
If successfully exploited, an attacker can force the victim to perform unintended actions within the plugin, such as triggering translation updates without the user's consent. This could lead to unauthorized changes in the site's translation files or other plugin-specific operations [1].
The vulnerability has been addressed in version 0.6.0 of the plugin. Users are strongly advised to update to this version or later. Patchstack users can enable auto-updates for vulnerable plugins to mitigate the risk [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<= 0.5+ 1 more
- (no CPE)range: <= 0.5
- (no CPE)range: <=0.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.