CVE-2025-23476
Published: 16 January 2025
Description
Cross-Site Request Forgery (CSRF) vulnerability in isnowfy my-related-posts my-related-posts allows Stored XSS.This issue affects my-related-posts: from n/a through <= 1.1.
Security Summary
CVE-2025-23476 is a Cross-Site Request Forgery (CSRF) vulnerability, classified under CWE-352, in the my-related-posts WordPress plugin developed by isnowfy. This flaw enables Stored Cross-Site Scripting (XSS) and affects all versions of the plugin up to and including 1.1. The vulnerability carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L), indicating network accessibility with low attack complexity.
Remote attackers without privileges can exploit the vulnerability by tricking authenticated users into visiting a malicious webpage that submits a forged request. This CSRF action leads to the storage of malicious scripts, enabling Stored XSS that can affect site visitors, including administrators, with low impacts on confidentiality, integrity, and availability due to the changed scope.
The Patchstack advisory at https://patchstack.com/database/Wordpress/Plugin/my-related-posts/vulnerability/wordpress-my-related-posts-plugin-1-1-csrf-to-stored-xss-vulnerability?_s_id=cve provides details on the vulnerability in the my-related-posts WordPress plugin version 1.1.
Details
- CWE(s)