Cross-Site Request Forgery Vulnerability in Hossni Mubarak Cool Author Box Plugin
CVE-2025-47447

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 May 2025

What is CVE-2025-47447?

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Hossni Mubarak Cool Author Box plugin. This vulnerability permits an attacker to exploit the user's authenticated session, potentially allowing unauthorized actions to be executed on behalf of the victim. Affected versions include all releases prior to 3.0.0, making it crucial for users of this plugin to update to the latest version to mitigate risks associated with this security flaw.

Affected Version(s)

Cool Author Box 0 <= 3.0.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.