
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67598 is a Cross-Site Request Forgery (CSRF) vulnerability in the SupportCandy WordPress plugin developed by PSM Plugins. It affects all versions of SupportCandy through 3.4.1 (inclusive). The vulnerability was published on December 9, 2025, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly, EUVD).
The vulnerability is classified under CWE-352 (Cross-Site Request Forgery), meaning the plugin fails to properly validate that state-changing requests originate from legitimate, authenticated user sessions. An attacker can craft a malicious web page or link that, when visited by an authenticated WordPress user (such as an administrator or support agent), triggers unauthorized actions within the SupportCandy plugin on their behalf. Exploitation requires no privileges on the part of the attacker but does require user interaction — specifically, a logged-in user must be tricked into visiting a malicious URL or page (Feedly, Patchstack).
Successful exploitation of this CSRF vulnerability allows an attacker to perform unauthorized actions within the SupportCandy plugin on behalf of an authenticated user, resulting in a low integrity impact with no direct confidentiality or availability consequences. Depending on the actions exposed without CSRF protection, this could include modifying support ticket data, changing plugin settings, or manipulating helpdesk workflows. The scope is limited to the affected WordPress installation and does not directly enable lateral movement or sensitive data exfiltration (Feedly).
There is no public evidence of active in-the-wild exploitation of CVE-2025-67598 at this time, and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No public proof-of-concept exploit code has been identified. The EPSS score is approximately 0.016% (0.000160), indicating a very low probability of exploitation in the near term (Feedly).
Users should update the SupportCandy WordPress plugin to a version beyond 3.4.1 that includes CSRF protection fixes. Until a patched version is available or applied, administrators can reduce risk by limiting access to the WordPress admin panel and SupportCandy functionality to trusted networks or IP ranges. Additionally, enforcing strict browser security policies (e.g., SameSite cookie attributes) at the server or CDN level can help mitigate CSRF risks as a temporary measure (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."