CVE-2025-67590
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67590 is a Cross-Site Request Forgery (CSRF) vulnerability in the Ultimate FAQ WordPress plugin developed by Rustaurius. It affects all versions of the plugin up to and including 2.4.3. The vulnerability was published on December 9, 2025, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly, Patchstack).

Technical details

The vulnerability is classified as CWE-352 (Cross-Site Request Forgery), meaning the plugin fails to properly validate or verify the origin of state-changing HTTP requests (Feedly). An attacker can craft a malicious web page or link that, when visited by an authenticated WordPress administrator or privileged user, silently submits forged requests to the plugin's endpoints on their behalf. No special privileges are required by the attacker, but user interaction (i.e., the victim clicking a link or visiting a malicious page) is necessary. No public proof-of-concept code has been identified at this time.

Impact

Successful exploitation allows an attacker to perform unauthorized actions within the Ultimate FAQ plugin on behalf of an authenticated user, resulting in limited integrity impact (CVSS integrity impact: Low). This could include modifying FAQ entries, settings, or other plugin-managed content without the victim's knowledge. Confidentiality and availability are not directly impacted by this vulnerability (Feedly).

Exploitation steps

  1. Reconnaissance: Identify a target WordPress site running the Ultimate FAQ plugin version 2.4.3 or earlier (e.g., by checking plugin metadata in publicly accessible WordPress files or using web scanning tools).
  2. Craft malicious request: Construct an HTML page or form that automatically submits a forged HTTP request to the vulnerable Ultimate FAQ plugin endpoint (e.g., a settings update or FAQ modification action) without a valid CSRF token.
  3. Deliver payload: Trick an authenticated WordPress administrator or privileged user into visiting the attacker-controlled page (e.g., via phishing email, malicious link, or embedded iframe).
  4. Trigger forged action: When the victim's browser loads the page, the forged request is sent automatically using the victim's active session cookies, causing the plugin to execute the unauthorized action (e.g., modifying FAQ content or plugin settings) on the victim's behalf.

Indicators of compromise

  • Logs: Unexpected POST requests to Ultimate FAQ plugin admin endpoints (e.g., /wp-admin/admin-post.php or admin-ajax.php with Ultimate FAQ action parameters) originating from unusual referrers or external domains in WordPress access logs.
  • File System: Unexplained changes to FAQ entries, plugin settings, or related database records without corresponding legitimate admin activity.
  • Network: HTTP requests to WordPress admin endpoints lacking a valid nonce/CSRF token field, or with a Referer header pointing to an external or unknown domain.

Mitigation and workarounds

Users should update the Ultimate FAQ plugin to a version above 2.4.3 that includes proper CSRF nonce validation. Until a patch is confirmed available, administrators can mitigate risk by restricting access to the WordPress admin panel (e.g., IP allowlisting), ensuring users are logged out when not actively administering the site, and using a web application firewall (WAF) capable of detecting CSRF patterns (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15991HIGH8.8
  • file-manager
NoYesAug 06, 2026
CVE-2026-15459HIGH8.1
  • wpmudev-updates
NoYesAug 06, 2026
CVE-2026-7529HIGH7.5
  • wisecampaign
NoYesAug 05, 2026
CVE-2026-18325HIGH7.2
  • forminator
NoYesAug 06, 2026
CVE-2026-16636HIGH7.2
  • fluent-smtp
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management