Cross-Site Request Forgery Risk in PixelYourSite for WordPress
CVE-2025-10588

4.3MEDIUM

What is CVE-2025-10588?

The PixelYourSite plugin for WordPress features a security flaw that allows attackers to exploit Cross-Site Request Forgery (CSRF) vulnerabilities. This issue stems from inadequate nonce validation in the adminEnableGdprAjax() function, which facilitates unauthorized changes to GDPR settings. Attackers can potentially manipulate these settings if they successfully deceive a site administrator into triggering a malicious action, such as clicking a crafted link. It is critical for administrators to ensure plugin updates are applied to mitigate this risk.

Affected Version(s)

PixelYourSite – Your smart PIXEL (TAG) & API Manager * <= 11.1.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.
CVE-2025-10588 : Cross-Site Request Forgery Risk in PixelYourSite for WordPress