VYPR
Medium severity4.3NVD Advisory· Published Sep 22, 2025· Updated Apr 23, 2026

CVE-2025-58675

CVE-2025-58675

Description

Cross-Site Request Forgery (CSRF) vulnerability in tryinteract Interact: Embed A Quiz On Your Site interact-quiz-embed allows Cross Site Request Forgery.This issue affects Interact: Embed A Quiz On Your Site: from n/a through <= 3.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A CSRF vulnerability in the Interact: Embed A Quiz On Your Site plugin (≤3.1) allows attackers to force privileged users to execute unwanted actions.

Vulnerability: Cross-Site Request Forgery (CSRF) in the Interact: Embed A Quiz On Your Site plugin for WordPress (versions up to and including 3.1). The root cause is a missing or insufficient CSRF token validation, which allows an attacker to craft malicious requests that are executed by an authenticated administrator without their consent [1].

Exploitation

To exploit this vulnerability, an attacker must trick a logged-in administrator into clicking a malicious link, visiting a crafted page, or submitting a specially crafted form. No other authentication is required beyond the victim's existing session. The attack is initiated remotely, and user interaction is required [1].

Impact

Successful exploitation could allow an attacker to perform unwanted actions under the victim's current authentication, such as changing plugin settings, deleting quizzes, or other administrative actions. The CVSS score of 4.3 (Medium) reflects the need for user interaction and the limited direct impact on data confidentiality or integrity [1].

Mitigation

The vulnerability has been addressed in version 3.2 of the plugin. Users are strongly advised to update to version 3.2 or later immediately. Patchstack users can enable auto-updates for vulnerable plugins. As this vulnerability is part of mass-exploit campaigns, prompt updating is critical [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.