Cyber Posture

CVE-2025-23476

High

Published: 16 January 2025

Published
16 January 2025
Modified
23 April 2026
KEV Added
Patch
CVSS Score 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS Score 0.0010 28.0th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Description

Cross-Site Request Forgery (CSRF) vulnerability in isnowfy my-related-posts my-related-posts allows Stored XSS.This issue affects my-related-posts: from n/a through <= 1.1.

Security Summary

CVE-2025-23476 is a Cross-Site Request Forgery (CSRF) vulnerability, classified under CWE-352, in the my-related-posts WordPress plugin developed by isnowfy. This flaw enables Stored Cross-Site Scripting (XSS) and affects all versions of the plugin up to and including 1.1. The vulnerability carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L), indicating network accessibility with low attack complexity.

Remote attackers without privileges can exploit the vulnerability by tricking authenticated users into visiting a malicious webpage that submits a forged request. This CSRF action leads to the storage of malicious scripts, enabling Stored XSS that can affect site visitors, including administrators, with low impacts on confidentiality, integrity, and availability due to the changed scope.

The Patchstack advisory at https://patchstack.com/database/Wordpress/Plugin/my-related-posts/vulnerability/wordpress-my-related-posts-plugin-1-1-csrf-to-stored-xss-vulnerability?_s_id=cve provides details on the vulnerability in the my-related-posts WordPress plugin version 1.1.

Details

CWE(s)
CWE-352

References