VYPR
Medium severity4.3NVD Advisory· Published Dec 22, 2025· Updated Apr 23, 2026

CVE-2025-62880

CVE-2025-62880

Description

Cross-Site Request Forgery (CSRF) vulnerability in Kunal Custom 404 Pro custom-404-pro allows Cross Site Request Forgery.This issue affects Custom 404 Pro: from n/a through <= 3.12.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A CSRF vulnerability in the Custom 404 Pro WordPress plugin (≤3.12.0) allows attackers to force privileged users to execute unwanted actions.

Vulnerability

Overview

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Custom 404 Pro WordPress plugin, versions 3.12.0 and earlier. The plugin fails to properly validate or enforce anti-CSRF tokens on state-changing requests, allowing an attacker to craft malicious requests that, when triggered by an authenticated administrator, perform unintended actions on the victim's behalf of that user [1].

Exploitation

Details

Exploitation requires user interaction: a privileged user (such as an administrator) must be tricked into clicking a malicious link, visiting a crafted page, or submitting a specially crafted form while authenticated to the WordPress site. No direct authentication is needed for the attacker, but the victim must have an active session with sufficient privileges to perform the targeted action [1].

Impact

Successful exploitation could allow an attacker to force the victim to execute unwanted actions under their current authentication level, such as modifying plugin settings, changing site options, or performing other administrative tasks without the victim's consent [1].

Mitigation

The vendor has released version 3.12.1 which addresses the vulnerability. Users are strongly advised to update to this version or later. Patchstack users can enable auto-updates for vulnerable plugins. While the vulnerability has a low severity rating and is considered unlikely to be exploited in mass campaigns, immediate updating is recommended as a precaution [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.