CVE-2025-54673: WordPress Chartify plugin <= 3.5.3 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Chartify allows Cross Site Request Forgery. This issue affects Chartify: from n/a through 3.5.3.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Chartify chart-builder allows Cross Site Request Forgery.This issue affects Chartify: from n/a through <= 3.5.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54673?
CVE-2025-54673 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can lead to unauthorized actions performed on behalf of a user.
How do I fix CVE-2025-54673?
To fix CVE-2025-54673, update Ays Pro Chartify or the WordPress Chartify Plugin to the latest version that is patched against this vulnerability.
Who is affected by CVE-2025-54673?
CVE-2025-54673 affects users of Ays Pro Chartify versions from n/a through 3.5.3 and the WordPress Chartify Plugin up to version 3.5.3.
What should I do if I can't upgrade to a patched version for CVE-2025-54673?
If unable to upgrade, consider disabling the affected plugin or implementing additional security measures to mitigate CSRF attacks.
Can CVE-2025-54673 be exploited remotely?
Yes, CVE-2025-54673 can be exploited remotely if an attacker can trick a user into performing unintended actions while authenticated.