Cross-Site Request Forgery Vulnerability in BSK Forms Blacklist by BannerSky
CVE-2025-22347

8.2HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
7 January 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the BSK Forms Blacklist plugin developed by BannerSky. This vulnerability allows attackers to exploit the plugin and perform Blind SQL Injection, potentially compromising the security and integrity of the data. This issue affects versions from n/a to 3.9, making it crucial for users to take immediate action to secure their installations.

Affected Version(s)

BSK Forms Blacklist <= 3.9

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

minhtuanact (Patchstack Alliance)
.