Description
Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate FAQ ultimate-faqs allows Cross Site Request Forgery.This issue affects Ultimate FAQ: from n/a through <= 2.4.3.
Published: 2025-12-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ultimate FAQ plugin released by Rustaurius contains a Cross‑Site Request Forgery flaw that permits an attacker to force an authenticated user to perform unintended actions through crafted requests. This can lead to unauthorized changes to FAQ entries, settings, or other protected resources, compromising data integrity and potentially exposing sensitive content. The weakness is identified as CWE‑352.

Affected Systems

All WordPress sites that have installed the Ultimate FAQ plugin version 2.4.3 or earlier are vulnerable. Any installation matched with the known product name “Rustaurius Ultimate FAQ” in that version range is affected.

Risk and Exploitability

The vulnerability carries a moderate CVSS score of 4.3 and an EPSS score of less than 1 %, indicating a low probability of exploitation at the time of assessment. It is not listed in the CISA KEV catalog. Exploitation would most likely occur through a web‑based attack that takes advantage of the lack of anti‑CSRF tokens, requiring a victim to be logged in and to visit a malicious link or form. Once achieved, the attacker can submit requests that alter or create content within the plugin’s scope.

Generated by OpenCVE AI on April 29, 2026 at 19:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Ultimate FAQ plugin to a version newer than 2.4.3 that includes CSRF protection.
  • If an upgrade is not possible, disable or remove the vulnerable plugin to eliminate the attack surface.
  • Deploy a web application firewall or similar controls that enforce anti‑CSRF checks for WordPress sites.

Generated by OpenCVE AI on April 29, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Thu, 22 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Rustaurius
Rustaurius ultimate Faq
Wordpress
Wordpress wordpress
Vendors & Products Rustaurius
Rustaurius ultimate Faq
Wordpress
Wordpress wordpress

Tue, 09 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate FAQ ultimate-faqs allows Cross Site Request Forgery.This issue affects Ultimate FAQ: from n/a through <= 2.4.3.
Title WordPress Ultimate FAQ plugin <= 2.4.3 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

Rustaurius Ultimate Faq
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:22.159Z

Reserved: 2025-12-09T12:21:39.681Z

Link: CVE-2025-67590

cve-icon Vulnrichment

Updated: 2025-12-09T21:03:33.081Z

cve-icon NVD

Status : Deferred

Published: 2025-12-09T16:18:37.073

Modified: 2026-04-27T17:16:42.690

Link: CVE-2025-67590

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T19:30:18Z

Weaknesses