VYPR
Medium severity4.3NVD Advisory· Published Dec 9, 2025· Updated Apr 27, 2026

CVE-2025-67598

CVE-2025-67598

Description

Cross-Site Request Forgery (CSRF) vulnerability in PSM Plugins SupportCandy supportcandy allows Cross Site Request Forgery.This issue affects SupportCandy: from n/a through <= 3.4.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF vulnerability in SupportCandy WordPress plugin up to 3.4.1 allows attackers to force privileged users to execute unwanted actions.

Vulnerability

Type A Cross-Site Request Forgery (CSRF) vulnerability exists in the SupportCandy plugin for WordPress, affecting versions from n/a through 3.4.1. The flaw arises from insufficient CSRF protections, enabling an attacker to trick authenticated users into performing unintended actions without their consent [1].

Exploitation

Prerequisites Exploitation requires user interaction — a privileged user must click a malicious link, visit a crafted page, or submit a deceptive form while authenticated. No authentication is needed for the attacker, but they rely on the victim's active session. The attack can be initiated by any role, though a higher-privileged user is targeted to maximize impact [1].

Impact

A successful CSRF attack could force a privileged user to execute unwanted actions under their current authentication, such as modifying plugin settings, creating new admin accounts, or performing other state-changing operations. This could lead to partial compromise of the WordPress site's functionality or security [1].

Mitigation

Users must update the SupportCandy plugin to version 3.4.2 or later, which resolves the issue. The vulnerability is rated as low severity with a CVSS v3 score of 4.3 and is unlikely to be widely exploited in mass campaigns. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.