Cross-Site Request Forgery Vulnerability in Easy Related Posts by WordPress
CVE-2025-25123
7.1HIGH
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Easy Related Posts plugin for WordPress, which can lead to Stored Cross-Site Scripting (XSS). This vulnerability allows attackers to perform unauthorized actions on behalf of a user without their consent, jeopardizing the security of WordPress sites running versions up to 2.0.2. Exploitation can result in malicious scripts being executed in the context of the user's session, potentially compromising sensitive data and user accounts.
Affected Version(s)
Easy Related Posts <= 2.0.2
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abdi Pranata (Patchstack Alliance)