VYPR
Medium severity4.3NVD Advisory· Published Sep 5, 2025· Updated Apr 23, 2026

CVE-2025-58831

CVE-2025-58831

Description

Cross-Site Request Forgery (CSRF) vulnerability in snagysandor Parallax Scrolling Enllax.js parallax-scrolling-enllax-js allows Cross Site Request Forgery.This issue affects Parallax Scrolling Enllax.js: from n/a through <= 0.0.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-Site Request Forgery (CSRF) vulnerability in Parallax Scrolling Enllax.js WordPress plugin versions <=0.0.6 allows attackers to force privileged users to execute unwanted actions.

The Parallax Scrolling Enllax.js WordPress plugin (versions up to and including 0.0.6) contains a Cross-Site Request Forgery (CSRF) vulnerability. The plugin fails to implement proper CSRF tokens or validation on sensitive actions, allowing an attacker to craft malicious requests that appear legitimate to the server [1].

Exploitation requires user interaction: a privileged user (such as an administrator) must be tricked into clicking a malicious link, visiting a crafted page, or submitting a specially designed form while authenticated to the WordPress site. No additional privileges are needed from the attacker beyond the ability to deliver the crafted request [1].

Successful CSRF attacks can force the victim to perform unintended actions under their current session, such as modifying plugin settings, deleting content, or creating new administrative users. This can lead to partial loss of integrity and availability, depending on the actions executed [1].

As an immediate mitigation, users should update the plugin to a patched version if available. If no update exists, administrators should consider disabling the plugin or implementing additional CSRF protections, such as using a Web Application Firewall (WAF) or custom nonce checks. Hosting providers or web developers can assist with these measures [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.