Cyber Posture

CVE-2025-23694

High

Published: 16 January 2025

Published
16 January 2025
Modified
23 April 2026
KEV Added
Patch
CVSS Score 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS Score 0.0015 35.3th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Description

Cross-Site Request Forgery (CSRF) vulnerability in shabboscommerce Shabbos and Yom Tov shabbos-and-yom-tov allows Stored XSS.This issue affects Shabbos and Yom Tov: from n/a through <= 1.9.

Security Summary

CVE-2025-23694 is a Cross-Site Request Forgery (CSRF) vulnerability, classified under CWE-352, in the Shabbos and Yom Tov WordPress plugin developed by shabboscommerce. This flaw enables Stored XSS and affects all versions of the plugin up to and including 1.9, with no known lower bound specified.

Unauthenticated attackers (PR:N) can exploit the vulnerability remotely over the network (AV:N) with low attack complexity (AC:L), though it requires user interaction (UI:R) such as tricking an administrator into submitting a malicious request. Successful exploitation changes the scope to high (S:C), allowing attackers to inject and store malicious scripts that execute in the context of other users viewing affected pages, resulting in low impacts to confidentiality, integrity, and availability (C:L/I:L/A:L) for a CVSS v3.1 base score of 7.1.

The Patchstack advisory documents this CSRF-to-Stored XSS issue in the Shabbos and Yom Tov plugin version 1.9 and provides details on the vulnerability for WordPress site operators.

Details

CWE(s)
CWE-352

References