VYPR
Medium severity4.3NVD Advisory· Published Dec 31, 2025· Updated Apr 23, 2026

CVE-2025-59130

CVE-2025-59130

Description

Cross-Site Request Forgery (CSRF) vulnerability in appointify Appointify appointify allows Cross Site Request Forgery.This issue affects Appointify: from n/a through <= 1.0.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF vulnerability in Appointify plugin (up to v1.0.8) allows attackers to force privileged users into unwanted actions.

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Appointify WordPress plugin through version 1.0.8. The vulnerability stems from missing or insufficient anti-CSRF tokens in sensitive operations, allowing an attacker to craft malicious requests that appear legitimate to the server [1].

Exploitation requires user interaction: a privileged user (e.g., an administrator) must be tricked into clicking a crafted link, visiting a malicious page, or submitting a form. The attacker does not need any authentication, but the target user must have an active session with the Appointify plugin [1].

Successful exploitation enables an attacker to perform unintended actions on behalf of the victim. This could include modifying plugin settings, deleting data, or other configuration changes, potentially leading to further compromise of the WordPress site [1].

Appointify users should immediately update the plugin to the latest patched version if available. As a workaround, implement additional CSRF protections such as adding nonces to forms and confirming sensitive actions. Plugin authors have been notified through Patchstack's disclosure process [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.