VYPR
Medium severity4.3NVD Advisory· Published Dec 9, 2025· Updated Apr 27, 2026

CVE-2025-67591

CVE-2025-67591

Description

Cross-Site Request Forgery (CSRF) vulnerability in jegtheme JNews Paywall jnews-paywall allows Cross Site Request Forgery.This issue affects JNews Paywall: from n/a through < 12.0.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF vulnerability in JNews Paywall plugin (WordPress) allows attackers to trick authenticated users into unintended actions; fixed in 12.0.1.

Vulnerability

Overview Cross-Site Request Forgery (CSRF) vulnerability in the JNews Paywall plugin for WordPress (versions from n/a through <12.0.1) allows attackers to perform unauthorized actions on behalf of authenticated users. The issue stems from missing or insufficient CSRF token validation, enabling malicious requests to be processed without user consent [1].

Exploitation

Exploitation requires a privileged user to perform an action such as clicking a malicious link, visiting a crafted page, or submitting a form. No authentication is needed for the attacker, but the victim must have an active session with the target WordPress site. The attack complexity is low, and the attack vector is network-based [1].

Impact

Successful exploitation could force a higher privileged user to execute unintended actions under their current authentication. This may include modifying plugin settings, disabling paywall features, or performing other administrative tasks, potentially compromising the integrity of the website [1].

Mitigation

The vulnerability has been patched in version 12.0.1 of the JNews Paywall plugin. Users are strongly advised to update to this version or later. Patchstack users can enable automatic updates for vulnerable plugins to ensure protection [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.