CVE-2025-62112
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-62112 is a Cross-Site Request Forgery (CSRF) vulnerability in the "Import into Easy Property Listings" WordPress plugin developed by Merv Barrett. It affects all versions up to and including 2.2.1, with version 2.2.2 containing the fix. The vulnerability was reported by researcher Nabil Irawan on October 9, 2025, and publicly disclosed by Patchstack on December 30, 2025. It carries a CVSS v3.1 base score of 4.3 (Medium) (Patchstack, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-352 (Cross-Site Request Forgery) and stems from missing or insufficient CSRF token validation on one or more plugin actions within the Import into Easy Property Listings plugin. An unauthenticated attacker can craft a malicious web page or link that, when visited by an authenticated WordPress administrator or privileged user, causes the victim's browser to submit unauthorized requests to the WordPress site on their behalf. The attack vector is network-based, requires no privileges from the attacker, but does require user interaction (a privileged user clicking a malicious link or visiting a crafted page) (Patchstack).

Impact

Successful exploitation allows an attacker to force higher-privileged WordPress users to execute unwanted actions under their current authentication session, such as modifying property listings or plugin settings. The impact is limited to integrity (low), with no direct confidentiality or availability impact. While the individual impact is low, Patchstack notes that CSRF vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously (Patchstack).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-62112. The EPSS score is approximately 0.014% (0.000140), indicating a very low probability of exploitation in the near term. The vulnerability is rated low priority by Patchstack and is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Patchstack, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "Import into Easy Property Listings" plugin at version 2.2.1 or earlier, using tools like WPScan or by inspecting publicly accessible plugin metadata.
  2. Craft malicious payload: Create an HTML page or form that automatically submits a forged HTTP request to the target WordPress site's vulnerable plugin endpoint (e.g., an import action), without including a valid CSRF nonce.
  3. Deliver to victim: Trick an authenticated WordPress administrator or privileged user into visiting the malicious page via phishing email, social engineering, or embedding the payload in a comment or external site.
  4. Trigger unauthorized action: When the victim's browser loads the malicious page, it automatically sends the forged request to the WordPress site using the victim's active session cookies, causing the plugin to execute the attacker-specified action (e.g., modifying property listings or import settings) (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unexpected POST requests to plugin-related admin endpoints (e.g., wp-admin/admin-post.php or wp-admin/admin.php with plugin-specific action parameters) from unusual referrer origins or with missing/invalid nonce values.
  • Application: Unexplained changes to property listings, import configurations, or plugin settings without corresponding administrator activity in the WordPress audit log.
  • Network: HTTP requests to WordPress admin endpoints originating from unexpected external referrer URLs, particularly those not matching the site's own domain.

Mitigation and workarounds

The vendor has released version 2.2.2 of the "Import into Easy Property Listings" plugin, which patches this CSRF vulnerability. Site administrators should update the plugin to version 2.2.2 or later immediately via the WordPress plugin dashboard. As a temporary workaround if updating is not immediately possible, administrators should avoid clicking links from untrusted sources while logged into WordPress, and consider using a security plugin such as Patchstack that provides virtual patching for known vulnerabilities (Patchstack).

Community reactions

The vulnerability was discovered and disclosed by Patchstack, with researcher Nabil Irawan credited for the responsible disclosure. Patchstack classifies this as low priority with no impactful threat, noting the issue is unlikely to be exploited in targeted attacks, though CSRF vulnerabilities broadly are used in mass-exploit campaigns against WordPress sites. No significant media coverage or notable researcher commentary beyond the Patchstack advisory has been identified (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78570CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78568CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78572HIGH8.1
  • kalles-addons
NoNoAug 25, 2026
CVE-2026-78576HIGH7.5
  • readabler
NoYesAug 25, 2026
CVE-2026-76128MEDIUM6.4
  • ecommerce-product-catalog
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management