Description
Cross-Site Request Forgery (CSRF) vulnerability in Mayo Moriyama Force Update Translations force-update-translations allows Cross Site Request Forgery.This issue affects Force Update Translations: from n/a through <= 0.5.
Published: 2025-09-22
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Force Update Translations plugin for WordPress contains a Cross‑Site Request Forgery (CSRF) vulnerability that allows an attacker to send forged requests to the site using an authenticated user's credentials. If exploited, the attacker can modify or delete site content, adjust settings, or otherwise perform any action that the logged‑in user is permitted to perform, thereby compromising the integrity of the website.

Affected Systems

The vulnerable plugin, Force Update Translations by Mayo Moriyama, is affected in all releases from the initial build up to and including version 0.5. The CVE entry does not list a fixed version beyond 0.5, so any installation of the plugin at version 0.5 or older remains vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium severity issue, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. It is inferred that the attacker must have access to a valid session cookie or persuade an authorized user to perform the action. The likely attack vector requires an authenticated WordPress user to be tricked into visiting a maliciously crafted link that submits a forged request on the site’s behalf. Because the flaw relies on CSRF, an effective defense is to ensure proper nonce validation on all state‑changing requests.

Generated by OpenCVE AI on April 30, 2026 at 15:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or uninstall the Force Update Translations plugin until a vendor patch is released.
  • Ensure that all other WordPress plugins and the core installation are updated to their latest versions to reduce the risk of overlapping vulnerabilities.
  • Implement WordPress nonce checks and CSRF defenses on all state‑changing requests, or use a security plugin that enforces strict request validation.

Generated by OpenCVE AI on April 30, 2026 at 15:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30583 Cross-Site Request Forgery (CSRF) vulnerability in Mayo Moriyama Force Update Translations allows Cross Site Request Forgery. This issue affects Force Update Translations: from n/a through 0.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Mayo Moriyama Force Update Translations allows Cross Site Request Forgery. This issue affects Force Update Translations: from n/a through 0.5. Cross-Site Request Forgery (CSRF) vulnerability in Mayo Moriyama Force Update Translations force-update-translations allows Cross Site Request Forgery.This issue affects Force Update Translations: from n/a through <= 0.5.
Title WordPress Force Update Translations Plugin <= 0.5 - Cross Site Request Forgery (CSRF) Vulnerability WordPress Force Update Translations plugin <= 0.5 - Cross Site Request Forgery (CSRF) vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 23 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Mayo Moriyama Force Update Translations allows Cross Site Request Forgery. This issue affects Force Update Translations: from n/a through 0.5.
Title WordPress Force Update Translations Plugin <= 0.5 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:42.700Z

Reserved: 2025-08-27T16:19:35.849Z

Link: CVE-2025-58236

cve-icon Vulnrichment

Updated: 2025-09-23T15:56:56.777Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:16:08.947

Modified: 2026-04-23T15:33:21.463

Link: CVE-2025-58236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T15:15:06Z

Weaknesses