VYPR
Medium severity4.3NVD Advisory· Published Sep 22, 2025· Updated Apr 23, 2026

CVE-2025-58236

CVE-2025-58236

Description

Cross-Site Request Forgery (CSRF) vulnerability in Mayo Moriyama Force Update Translations force-update-translations allows Cross Site Request Forgery.This issue affects Force Update Translations: from n/a through <= 0.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF vulnerability in WordPress Force Update Translations plugin (<=0.5) allows attackers to force privileged users to execute unwanted actions.

The Force Update Translations plugin for WordPress (versions 0.5 and earlier) contains a Cross-Site Request Forgery (CSRF) vulnerability. The plugin fails to implement proper CSRF tokens or validation on certain administrative actions, allowing an attacker to craft malicious requests that are executed under the authentication of a privileged user [1].

Exploitation requires user interaction: a privileged user (such as an administrator) must be tricked into clicking a malicious link, visiting a crafted page, or submitting a form while authenticated to the WordPress admin panel. The attack can be initiated remotely without any special privileges, but the victim must perform the action [1].

If successfully exploited, an attacker can force the victim to perform unintended actions within the plugin, such as triggering translation updates without the user's consent. This could lead to unauthorized changes in the site's translation files or other plugin-specific operations [1].

The vulnerability has been addressed in version 0.6.0 of the plugin. Users are strongly advised to update to this version or later. Patchstack users can enable auto-updates for vulnerable plugins to mitigate the risk [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.