CVE-2025-58833
8.8INVELITY · MyGLS connect
A Cross-Site Request Forgery (CSRF) vulnerability in the INVELITY MyGLS connect plugin allows for Object Injection.
Executive summary
A critical CSRF vulnerability in the INVELITY MyGLS connect plugin allows unauthenticated attackers to perform unauthorized actions, potentially leading to object injection and full system compromise.
Vulnerability
The plugin is susceptible to Cross-Site Request Forgery (CWE-352), which can be exploited by an unauthenticated attacker to inject objects into the application. This occurs because the application fails to adequately verify the authenticity of requests, allowing an attacker to trick a logged-in user into executing unintended actions.
Business impact
The ability to perform object injection through a CSRF attack poses a severe risk to data integrity and system availability. Given the CVSS score of 8.8, this vulnerability allows an attacker to achieve high levels of impact on confidentiality, integrity, and availability. Successful exploitation could lead to unauthorized administrative actions, data exfiltration, or complete disruption of the affected service.
Remediation
Immediate Action: Since a specific patch version is currently unknown, administrators should prioritize disabling or removing the Invelity MyGLS connect plugin until a secure update is confirmed by the vendor.
Proactive Monitoring: Review web server access logs for suspicious POST requests originating from unexpected sources or lacking valid anti-CSRF tokens.
Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to detect and block malicious CSRF patterns and unauthorized object injection attempts.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability represents a significant security risk to any WordPress environment utilizing the MyGLS connect plugin. Due to the high severity score, immediate action is required to minimize the attack surface. We strongly recommend disabling the plugin immediately and monitoring the vendor's security advisory page for the release of a patched version.
More INVELITY CVEs
Sources
Originally found and disclosed by Martino Spagnuolo (r3verii) | Patchstack Bug Bounty Program, per the CVE Program record.