CVE-2025-58865
Description
Cross-Site Request Forgery (CSRF) vulnerability in reimund Compact Admin compact-admin allows Cross Site Request Forgery.This issue affects Compact Admin: from n/a through <= 1.3.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cross-Site Request Forgery (CSRF) vulnerability in Compact Admin plugin (<=1.3.3) allows unauthenticated attackers to force privileged users to execute unwanted actions.
Vulnerability
Overview A Cross-Site Request Forgery (CSRF) vulnerability exists in the Compact Admin plugin for WordPress, affecting versions 1.3.3 and earlier. The plugin fails to implement proper nonce validation on certain actions, allowing an attacker to craft malicious requests that are executed under the authentication of a privileged user [1].
Attack
Vector Exploitation requires a privileged user to perform an action such as clicking a malicious link, visiting a crafted page, or submitting a form. An unauthenticated attacker can craft a request (e.g., to change settings) and trick a logged-in administrator into submitting it. No direct authentication is needed for the attacker, but user interaction is required [1].
Impact
Successful exploitation could allow an attacker to force higher-privileged users to execute unwanted actions under their current session, potentially leading to unauthorized changes in plugin settings or other administrative actions. The CVSS score is 4.3 (Medium) [1].
Mitigation
The vendor has not released a patch as of the publication date. Users are advised to update the plugin if a new version becomes available, or seek assistance from their hosting provider or web developer. This vulnerability is known to be used in mass-exploit campaigns [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.