CVE-2025-68082
Description
Cross-Site Request Forgery (CSRF) vulnerability in SEMrush CY LTD Semrush Content Toolkit semrush-contentshake allows Cross Site Request Forgery.This issue affects Semrush Content Toolkit: from n/a through <= 1.1.32.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The WordPress Semrush Content Toolkit plugin <=1.1.32 contains a CSRF vulnerability allowing attackers to force privileged users to execute unwanted actions.
Vulnerability
Overview
The Semrush Content Toolkit (semrush-contentshake) plugin for WordPress, version 1.1.32 and earlier, is affected by a Cross-Site Request Forgery (CSRF) vulnerability. This flaw stems from insufficient validation of HTTP requests, enabling an attacker to trick an authenticated administrative user into performing unintended actions [1].
Exploitation
Exploitation requires user interaction—an attacker must convince a privileged user (such as an admin) to click a crafted link or visit a malicious page while authenticated to the WordPress site. No additional privileges are required beyond the victim's existing session [1].
Impact
If exploited, an attacker can force the target user to execute state-changing operations under their own authentication, such as modifying plugin settings or performing other undesired actions. This could lead to partial compromise of the affected website's content configuration [1].
Mitigation
The vendor has released version 1.1.33 which fixes the CSRF vulnerability. Users are strongly advised to update immediately [1]. For Patchstack users, enabling auto-updates for vulnerable plugins provides ongoing protection against mass-exploitation campaigns known to target this type of issue [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.1.32
- Range: <=1.1.32
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.