CVE-2025-68573: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68573 is a Cross-Site Request Forgery (CSRF) vulnerability in the Simple Keyword to Link WordPress plugin developed by Alessandro Piconi. It affects all versions of the plugin up to and including version 1.5. The vulnerability was published on December 24, 2025, and assigned by Patchstack. It carries a CVSS v3.1 base score of 5.4 (Medium) (Red Hat CVE, Feedly).

Technical details

The vulnerability is classified as CWE-352 (Cross-Site Request Forgery), arising from the plugin's failure to implement adequate CSRF token validation on sensitive administrative actions. An attacker can craft a malicious webpage containing a forged HTTP request targeting the plugin's administrative endpoints; when an authenticated WordPress administrator visits the page, the browser automatically includes session credentials, causing the forged request to execute with the admin's privileges. No special privileges are required by the attacker, but user interaction (an authenticated admin visiting the malicious page) is a prerequisite for exploitation (Red Hat CVE, Feedly).

Impact

Successful exploitation allows an attacker to perform unauthorized administrative actions within the Simple Keyword to Link plugin on behalf of an authenticated WordPress administrator, including modifying plugin settings, altering keyword-to-link mappings, or deleting configurations. The confidentiality impact is none, while integrity and availability are both rated low. The scope is limited to the affected plugin's functionality and does not directly enable remote code execution or lateral movement (Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Simple Keyword to Link plugin version 1.5 or earlier, using tools such as WPScan or manual inspection of plugin directories.
  2. Craft malicious page: Create an HTML page containing a hidden form or JavaScript that automatically submits a forged POST request to the target WordPress site's admin endpoint for the Simple Keyword to Link plugin (e.g., wp-admin/options-general.php?page=simple-keyword-to-link).
  3. Embed forged action: Include the desired malicious parameters in the form (e.g., modifying keyword-to-link settings or deleting configurations) without a valid CSRF nonce, exploiting the plugin's lack of token validation.
  4. Deliver to victim: Trick an authenticated WordPress administrator into visiting the malicious page via phishing email, social engineering, or a compromised third-party site.
  5. Action executes: The administrator's browser automatically sends the forged request with their active session cookies, causing the plugin to process the unauthorized action as if initiated by the admin (Feedly).

Indicators of compromise

  • Logs: WordPress access logs showing unexpected POST requests to plugin admin pages (e.g., wp-admin/options-general.php?page=simple-keyword-to-link) from unusual referrer URLs or external domains.
  • Application: Unexpected changes to Simple Keyword to Link plugin settings, keyword mappings, or configurations without corresponding administrator activity.
  • Network: HTTP requests to WordPress admin endpoints originating from external or unfamiliar referrer headers, particularly with no valid nonce values in the request body.

Mitigation and workarounds

Users should update the Simple Keyword to Link plugin to the latest available version beyond 1.5, which is expected to include proper CSRF nonce validation. As interim measures, administrators should use a WordPress security plugin that provides additional CSRF protection, restrict plugin access using the principle of least privilege, and avoid clicking links from untrusted sources while logged into the WordPress admin panel. Disabling the plugin until a patched version is available is also a viable option for high-risk environments (Feedly, Red Hat CVE).

Community reactions

The vulnerability received limited coverage, with brief mentions on TheHackerWire and social media platforms including Mastodon (infosec.exchange) and Bluesky shortly after disclosure. RedPacket Security included it in a weekly CISA vulnerability summary for the week of December 22, 2025. No significant vendor statements or notable researcher commentary beyond the Patchstack disclosure have been identified (Feedly).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management