CVE-2025-58244
8.8Anps Constructo · Constructo
A Cross-Site Request Forgery (CSRF) vulnerability in the Anps Constructo theme allows for Object Injection, potentially leading to unauthorized actions or code execution.
Executive summary
An unauthenticated Cross-Site Request Forgery vulnerability in the Anps Constructo theme poses a high risk of unauthorized object injection and system compromise.
Vulnerability
This vulnerability is a Cross-Site Request Forgery (CWE-352) that allows an unauthenticated attacker to trick a logged-in administrator into performing unintended actions. By leveraging this flaw, an attacker can trigger Object Injection within the application, which may lead to significant impacts on the integrity and availability of the system.
Business impact
Successful exploitation of this vulnerability can lead to complete system compromise, including unauthorized data modification or total loss of service. Given the CVSS score of 8.8, this flaw represents a high-severity risk that could result in severe reputational damage and operational disruption if exploited to inject malicious objects into the environment.
Remediation
Immediate Action: Since no specific patch version is currently confirmed, administrators should immediately audit the use of the Constructo theme and consider deactivating it if it is not essential to business operations.
Proactive Monitoring: Monitor server access logs for suspicious POST requests originating from unexpected sources, particularly those directed at administrative endpoints or theme-specific configuration files.
Compensating Controls: Deploy a Web Application Firewall (WAF) configured to inspect and block suspicious incoming requests that lack proper anti-CSRF tokens or exhibit signs of object injection attempts.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
The high CVSS score of 8.8 necessitates prompt attention to this vulnerability to prevent potential object injection attacks. Organizations using the Constructo theme should restrict access to administrative interfaces and prioritize the application of any forthcoming vendor security updates that address this CSRF flaw.
Sources
Originally found and disclosed by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program, per the CVE Program record.