CVE-2025-58869
Description
Cross-Site Request Forgery (CSRF) vulnerability in Simasicher SimaCookie simasicher-dsgvo-cookie allows Stored XSS.This issue affects SimaCookie: from n/a through <= 1.3.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CSRF vulnerability in SimaCookie WordPress plugin allows attackers to perform Stored XSS by tricking privileged users into malicious actions.
The SimaCookie plugin for WordPress (versions up to and including 1.3.2) contains a Cross-Site Request Forgery (CSRF) vulnerability that can lead to Stored Cross-Site Scripting (XSS). The root cause is insufficient CSRF protection, allowing an attacker to forge requests on behalf of an authenticated administrator without their consent [1].
Exploitation requires a privileged user, such as an administrator, to be tricked into clicking a malicious link or visiting a crafted page while authenticated. The attacker can then perform actions like injecting malicious scripts into the plugin's settings, which are stored and executed when other users view the affected pages. No direct authentication is needed for the attacker, but the victim must have elevated privileges [1].
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser, potentially leading to session hijacking, defacement, or further compromise of the WordPress site. This vulnerability is noted as being used in mass-exploit campaigns, targeting thousands of sites regardless of size or popularity [1].
As immediate action, users should update the plugin to a patched version if available. If unable to update, contacting the hosting provider or web developer for assistance is recommended. The Patchstack advisory provides full details and mitigation guidance [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=1.3.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.