CVE-2025-23810
Published: 16 January 2025
Description
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Security Summary
CVE-2025-23810 is a Cross-Site Request Forgery (CSRF) vulnerability in the Len Slider WordPress plugin by Igor Sazonov, which allows Reflected Cross-Site Scripting (XSS). This issue affects Len Slider versions from n/a through 2.0.11 and is associated with CWE-352.
Unauthenticated attackers can exploit this vulnerability remotely with low attack complexity and no required privileges, but it necessitates user interaction. Exploitation enables reflected XSS through CSRF, achieving low impacts on confidentiality, integrity, and availability with a changed scope, as reflected in its CVSS 3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).
The Patchstack advisory documents this CSRF to reflected XSS vulnerability in WordPress Len Slider plugin 2.0.11 and provides details on mitigation, available at https://patchstack.com/database/Wordpress/Plugin/len-slider/vulnerability/wordpress-len-slider-plugin-2-0-11-csrf-to-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve.
Details
- CWE(s)
MITRE ATT&CK Enterprise Techniques
Why these techniques?
The CSRF to reflected XSS vulnerability in the public-facing WordPress plugin directly enables remote exploitation of a public-facing application.