
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68573 is a Cross-Site Request Forgery (CSRF) vulnerability in the Simple Keyword to Link WordPress plugin developed by Alessandro Piconi. It affects all versions of the plugin up to and including version 1.5. The vulnerability was published on December 24, 2025, and assigned by Patchstack. It carries a CVSS v3.1 base score of 5.4 (Medium) (Red Hat CVE, Feedly).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery), arising from the plugin's failure to implement adequate CSRF token validation on sensitive administrative actions. An attacker can craft a malicious webpage containing a forged HTTP request targeting the plugin's administrative endpoints; when an authenticated WordPress administrator visits the page, the browser automatically includes session credentials, causing the forged request to execute with the admin's privileges. No special privileges are required by the attacker, but user interaction (an authenticated admin visiting the malicious page) is a prerequisite for exploitation (Red Hat CVE, Feedly).
Successful exploitation allows an attacker to perform unauthorized administrative actions within the Simple Keyword to Link plugin on behalf of an authenticated WordPress administrator, including modifying plugin settings, altering keyword-to-link mappings, or deleting configurations. The confidentiality impact is none, while integrity and availability are both rated low. The scope is limited to the affected plugin's functionality and does not directly enable remote code execution or lateral movement (Feedly).
There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term (Feedly).
wp-admin/options-general.php?page=simple-keyword-to-link).wp-admin/options-general.php?page=simple-keyword-to-link) from unusual referrer URLs or external domains.Users should update the Simple Keyword to Link plugin to the latest available version beyond 1.5, which is expected to include proper CSRF nonce validation. As interim measures, administrators should use a WordPress security plugin that provides additional CSRF protection, restrict plugin access using the principle of least privilege, and avoid clicking links from untrusted sources while logged into the WordPress admin panel. Disabling the plugin until a patched version is available is also a viable option for high-risk environments (Feedly, Red Hat CVE).
The vulnerability received limited coverage, with brief mentions on TheHackerWire and social media platforms including Mastodon (infosec.exchange) and Bluesky shortly after disclosure. RedPacket Security included it in a weekly CISA vulnerability summary for the week of December 22, 2025. No significant vendor statements or notable researcher commentary beyond the Patchstack disclosure have been identified (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."