VYPR
Medium severity6.5NVD Advisory· Published Dec 9, 2025· Updated Apr 27, 2026

CVE-2025-62739

CVE-2025-62739

Description

Cross-Site Request Forgery (CSRF) vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Cross Site Request Forgery.This issue affects Add Custom Codes: from n/a through <= 4.80.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF in Add Custom Codes plugin (≤4.80) lets attackers force privileged users to execute unwanted actions via crafted requests.

Vulnerability

Overview

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress plugin Add Custom Codes, versions from n/a through 4.80. The plugin fails to validate or verify requests made by authenticated users, allowing an attacker to craft malicious requests that are executed under the identity of a higher-privileged user [1].

Exploitation

Exploitation requires user interaction: a privileged user (such as an administrator) must be tricked into clicking a malicious link, visiting a crafted page, or submitting a form while authenticated to the WordPress site. No additional authentication is needed for the attacker beyond the victim's existing session [1].

Impact

Successful exploitation allows an attacker to force the victim to perform unintended actions within the plugin'such as modifying plugin settings, adding malicious code, or other administrative operations'within the context of the victim's session. This can lead to partial loss of integrity and availability, though the CVSS score of 6.5 (Medium) reflects a moderate impact [1].

Mitigation

The vulnerability is patched in version 5.0 or later. Users are strongly advised to update immediately. If updating is not possible, contacting the hosting provider or a web developer for assistance is recommended. Patchstack users can enable auto-updates for vulnerable plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.