VYPR
Medium severity4.3NVD Advisory· Published Sep 5, 2025· Updated Apr 23, 2026

CVE-2025-58865

CVE-2025-58865

Description

Cross-Site Request Forgery (CSRF) vulnerability in reimund Compact Admin compact-admin allows Cross Site Request Forgery.This issue affects Compact Admin: from n/a through <= 1.3.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-Site Request Forgery (CSRF) vulnerability in Compact Admin plugin (<=1.3.3) allows unauthenticated attackers to force privileged users to execute unwanted actions.

Vulnerability

Overview A Cross-Site Request Forgery (CSRF) vulnerability exists in the Compact Admin plugin for WordPress, affecting versions 1.3.3 and earlier. The plugin fails to implement proper nonce validation on certain actions, allowing an attacker to craft malicious requests that are executed under the authentication of a privileged user [1].

Attack

Vector Exploitation requires a privileged user to perform an action such as clicking a malicious link, visiting a crafted page, or submitting a form. An unauthenticated attacker can craft a request (e.g., to change settings) and trick a logged-in administrator into submitting it. No direct authentication is needed for the attacker, but user interaction is required [1].

Impact

Successful exploitation could allow an attacker to force higher-privileged users to execute unwanted actions under their current session, potentially leading to unauthorized changes in plugin settings or other administrative actions. The CVSS score is 4.3 (Medium) [1].

Mitigation

The vendor has not released a patch as of the publication date. Users are advised to update the plugin if a new version becomes available, or seek assistance from their hosting provider or web developer. This vulnerability is known to be used in mass-exploit campaigns [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.