CVE-2025-62089
Description
Cross-Site Request Forgery (CSRF) vulnerability in MERGADO Mergado Pack mergado-marketing-pack allows Cross Site Request Forgery.This issue affects Mergado Pack: from n/a through <= 4.2.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CSRF vulnerability in Mergado Pack plugin (≤4.2.1) allows attackers to force privileged users to execute unwanted actions.
The Mergado Pack plugin (mergado-marketing-pack) for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions from n/a through 4.2.1 [1]. This issue stems from missing or insufficient CSRF token validation, allowing an attacker to trick a logged-in administrator into performing unintended actions [1].
Exploitation requires user interaction: a privileged user must click a malicious link or submit a crafted form while authenticated to the WordPress dashboard [1]. The attack can be initiated by a low-privileged role, but the actual CSRF payload executes with the victim's privileges [1]. No other prerequisites such as network access are specified beyond the need for the victim to be logged in.
Successful exploitation could allow an attacker to force higher-privileged users (e.g., administrators) to execute unwanted actions under their current session, such as changing plugin settings, modifying content, or other configuration changes [1]. The CVSS v3 base score is 4.3 (Medium), emphasizing the need for user interaction and the potential for limited impact [1].
PatchStack recommends updating the plugin immediately to a version higher than 4.2.1 as a mitigation [1]. No workarounds are listed; users unable to update should seek assistance from their hosting provider or web developer [1]. This vulnerability is noted as being used in mass-exploit campaigns, stressing the urgency of patching [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=4.2.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.