Description
Cross-Site Request Forgery (CSRF) vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Cross Site Request Forgery.This issue affects Add Custom Codes: from n/a through <= 4.80.
Published: 2025-12-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery vulnerability exists in SaifuMak Add Custom Codes that permits an attacker to force an authenticated user to perform arbitrary actions within the plugin. Because the plugin’s actions lack proper CSRF protections, a malicious site can cause a victim’s browser to submit requests that modify content or change configuration without the user’s consent. This leads to potential loss of confidentiality, integrity, and availability of site data and can be leveraged for further exploitation.

Affected Systems

The vulnerability affects the SaifuMak Add Custom Codes WordPress plugin at all releases from the earliest available version through version 4.80. Any website running this plugin up to, and including, 4.80 is susceptible; versions newer than 4.80 are not mentioned as affected.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity flaw, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The issue is not listed in CISA’s KEV catalog. Exploitation requires a user to be logged into the WordPress site and a crafted request to trigger a plugin action. The likely attack vector is a malicious website inducing a victim’s browser to make a POST request to the vulnerable endpoint, potentially escalating the attacker’s reach to administrative functions if the victim has such privileges.

Generated by OpenCVE AI on April 29, 2026 at 19:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Add Custom Codes plugin to the latest available version, which should remove the CSRF protection flaw.
  • If upgrading immediately is not feasible, implement additional server‑side CSRF token checks for requests that alter plugin data or establish firewall rules to block suspicious POST requests targeting the plugin’s endpoints.
  • Restrict administrative and plugin configuration access to trusted users by enforcing strong authentication, enabling two‑factor authentication, and monitoring for anomalous request patterns to mitigate accidental exploitation.

Generated by OpenCVE AI on April 29, 2026 at 19:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 11 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 09 Dec 2025 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Cross Site Request Forgery.This issue affects Add Custom Codes: from n/a through <= 4.80.
Title WordPress Add Custom Codes plugin <= 4.80 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:03.707Z

Reserved: 2025-10-21T14:59:44.294Z

Link: CVE-2025-62739

cve-icon Vulnrichment

Updated: 2025-12-11T18:55:35.323Z

cve-icon NVD

Status : Deferred

Published: 2025-12-09T16:18:02.753

Modified: 2026-04-27T18:16:26.440

Link: CVE-2025-62739

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T19:30:18Z

Weaknesses