VYPR
Medium severity4.3NVD Advisory· Published Dec 16, 2025· Updated Apr 27, 2026

CVE-2025-64237

CVE-2025-64237

Description

Cross-Site Request Forgery (CSRF) vulnerability in Graham Quick Interest Slider quick-interest-slider allows Cross Site Request Forgery.This issue affects Quick Interest Slider: from n/a through <= 3.1.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-Site Request Forgery (CSRF) vulnerability in WordPress Quick Interest Slider plugin up to version 3.1.5 allows attackers to force privileged users to execute unwanted actions.

Vulnerability

Overview

The Quick Interest Slider plugin for WordPress, versions 3.1.5 and earlier, contains a Cross-Site Request Forgery (CSRF) vulnerability. This flaw arises from insufficient CSRF protection on certain plugin actions, allowing an attacker to craft malicious requests that appear legitimate to the server [1].

Exploitation

To exploit this vulnerability, an attacker must trick a privileged user, such as an administrator, into performing an action like clicking a malicious link or visiting a crafted page. The attacker does not need direct access to the WordPress site but relies on the victim's active session to execute unauthorized commands [1].

Impact

Successful exploitation enables the attacker to perform actions under the victim's authentication, such as modifying plugin settings, adding or deleting content, or other administrative tasks. This could lead to partial compromise of the site's integrity and functionality [1].

Mitigation

The vulnerability has been addressed in version 3.1.6 of the plugin. Users are strongly advised to update immediately. While Patchstack notes the severity as low and exploitation as unlikely, proactive updating is recommended to prevent potential mass-exploit campaigns [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.