VYPR
Medium severity4.3NVD Advisory· Published Sep 26, 2025· Updated Apr 23, 2026

CVE-2025-60115

CVE-2025-60115

Description

Cross-Site Request Forgery (CSRF) vulnerability in instapagedev Instapage Plugin instapage allows Cross Site Request Forgery.This issue affects Instapage Plugin: from n/a through <= 3.7.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-Site Request Forgery in Instapage WordPress plugin allows attackers to force privileged users to execute unwanted actions, patched in 3.7.1.

Vulnerability

Overview

The Instapage WordPress plugin (versions up to 3.7.0) is vulnerable to Cross-Site Request Forgery (CSRF). This type of vulnerability occurs when the plugin fails to properly validate nonces or implement anti-CSRF tokens, allowing an attacker to craft requests that appear to come from an authenticated user [1].

Exploitation

Prerequisites

Exploitation requires an authenticated user with higher privileges (such as an administrator) to be tricked into clicking a malicious link, visiting a crafted page, or submitting a form. The attacker does not need authentication but relies on the victim's active session to execute unauthorized actions [1].

Impact

A successful CSRF attack can force the victim to perform unintended actions under their current authentication, such as changing plugin settings, deactivating the plugin, or other administrative actions. This vulnerability is noted to be used in mass-exploit campaigns targeting thousands of websites [1].

Mitigation

The issue is patched in version 3.7.1. Users are advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. The CVSS score is 4.3 (Medium), and while exploitation is unlikely, immediate action is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.