VYPR
Medium severity4.3NVD Advisory· Published Sep 26, 2025· Updated Apr 23, 2026

CVE-2025-60113

CVE-2025-60113

Description

Cross-Site Request Forgery (CSRF) vulnerability in grooni Groovy Menu groovy-menu-free allows Cross Site Request Forgery.This issue affects Groovy Menu: from n/a through <= 1.4.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-Site Request Forgery (CSRF) vulnerability in Groovy Menu plugin for WordPress allows attackers to force privileged users to execute unintended actions.

Vulnerability

Description A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Groovy Menu plugin (groovy-menu-free) up to version 1.4.3. The flaw occurs due to insufficient protection against forged requests, enabling attackers to trick authenticated users into performing actions they did not intend [1].

Exploitation

Attackers can exploit this vulnerability by crafting malicious links, pages, or forms that, when interacted with by a privileged user (e.g., admin), trigger unwanted actions under the victim's current authentication. The attack requires user interaction, such as clicking a link or submitting a form, but no special privileges aside from social engineering [1].

Impact

Successful exploitation allows an attacker to force higher-privileged users to execute actions on the WordPress site, such as modifying settings, creating new admin accounts, or injecting malicious content. This could lead to full site compromise if chained with other vulnerabilities [1].

Mitigation

The vendor has released updates to address this issue. Users are strongly advised to update the plugin to the latest version. If updating is not immediately possible, users should consult their hosting provider or a web developer for assistance. This vulnerability is known to be targeted in mass exploitation campaigns, making timely patching critical [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.