VYPR
Medium severity4.3NVD Advisory· Published Dec 31, 2025· Updated Apr 23, 2026

CVE-2025-62089

CVE-2025-62089

Description

Cross-Site Request Forgery (CSRF) vulnerability in MERGADO Mergado Pack mergado-marketing-pack allows Cross Site Request Forgery.This issue affects Mergado Pack: from n/a through <= 4.2.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF vulnerability in Mergado Pack plugin (≤4.2.1) allows attackers to force privileged users to execute unwanted actions.

The Mergado Pack plugin (mergado-marketing-pack) for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions from n/a through 4.2.1 [1]. This issue stems from missing or insufficient CSRF token validation, allowing an attacker to trick a logged-in administrator into performing unintended actions [1].

Exploitation requires user interaction: a privileged user must click a malicious link or submit a crafted form while authenticated to the WordPress dashboard [1]. The attack can be initiated by a low-privileged role, but the actual CSRF payload executes with the victim's privileges [1]. No other prerequisites such as network access are specified beyond the need for the victim to be logged in.

Successful exploitation could allow an attacker to force higher-privileged users (e.g., administrators) to execute unwanted actions under their current session, such as changing plugin settings, modifying content, or other configuration changes [1]. The CVSS v3 base score is 4.3 (Medium), emphasizing the need for user interaction and the potential for limited impact [1].

PatchStack recommends updating the plugin immediately to a version higher than 4.2.1 as a mitigation [1]. No workarounds are listed; users unable to update should seek assistance from their hosting provider or web developer [1]. This vulnerability is noted as being used in mass-exploit campaigns, stressing the urgency of patching [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.