CVE-2025-58270
7.1NIX Solutions Ltd · NIX Anti-Spam Light
A Cross-Site Request Forgery vulnerability in the NIX Anti-Spam Light plugin allows unauthorized actions to be performed on behalf of an authenticated user.
Executive summary
A Cross-Site Request Forgery vulnerability in the NIX Anti-Spam Light WordPress plugin poses a risk of unauthorized administrative actions.
Vulnerability
This flaw is a Cross-Site Request Forgery (CWE-352) vulnerability that allows an unauthenticated attacker to trick a logged-in administrator into performing unintended actions within the plugin. The vulnerability exists due to a lack of proper request validation.
Business impact
The successful exploitation of this vulnerability could lead to unauthorized configuration changes or other administrative actions within the WordPress environment. Given the CVSS score of 7.1, this represents a high risk to the integrity and availability of the affected website, potentially leading to unauthorized plugin settings modification or service disruption.
Remediation
Immediate Action: Since no specific patch version is currently identified, administrators should monitor the official Patchstack database or the WordPress plugin repository for updates. If a fix is not available, consider deactivating the plugin until a secure version is released.
Proactive Monitoring: Review web server access logs for suspicious requests originating from unauthorized sources that target plugin configuration endpoints.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block suspicious cross-site requests to mitigate the risk of exploitation.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the severity of CSRF vulnerabilities in administrative contexts, users of NIX Anti-Spam Light should exercise caution. Until a vendor-supplied patch is released, ensure that administrative sessions are not left unattended and consider disabling the plugin to eliminate the attack surface entirely.
More NIX Solutions Ltd CVEs
Sources
Originally found and disclosed by Nguyen Xuan Chien | Patchstack Bug Bounty Program, per the CVE Program record.