VYPR
Medium severity4.3NVD Advisory· Published Dec 9, 2025· Updated Apr 15, 2026

CVE-2025-62872

CVE-2025-62872

Description

Cross-Site Request Forgery (CSRF) vulnerability in JK Social Photo Fetcher facebook-photo-fetcher allows Cross Site Request Forgery.This issue affects Social Photo Fetcher: from n/a through <= 3.0.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF vulnerability in WordPress Social Photo Fetcher plugin (≤3.0.4) allows attackers to force privileged users to perform unwanted actions.

Vulnerability

Overview The Social Photo Fetcher plugin for WordPress (versions up to and including 3.0.4) contains a Cross-Site Request Forgery (CSRF) vulnerability due to missing or insufficient nonce validation. This flaw enables an attacker to trick a logged-in administrator into executing unintended actions without their consent, as the plugin fails to verify the authenticity of requests [1].

Exploitation

Prerequisites Exploitation requires social engineering: the attacker must convince a privileged user—such as an administrator—to click on a crafted link, visit a malicious page, or submit a form while they are authenticated to the WordPress site. No additional privileges are needed from the attacker, and the attack can be initiated remotely without authentication [1].

Impact

If successfully exploited, the attacker can force the victim to perform actions under their current session, such as changing plugin settings, importing malicious data, or deleting photos. This could potentially lead to further compromise of the WordPress installation, especially if combined with other vulnerabilities [1].

Mitigation

The vulnerability has been patched in version 3.0.5 or later. Users are strongly advised to update the plugin immediately. If updating is not possible, consider disabling the plugin or implementing additional security measures such as Web Application Firewall (WAF) rules to block CSRF attempts [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.