Cross-Site Request Forgery in Navayan Subscribe by Amol Nirmala Waman
CVE-2025-53311

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 June 2025

What is CVE-2025-53311?

The Navayan Subscribe plugin suffers from a Cross-Site Request Forgery (CSRF) vulnerability, which can lead to stored cross-site scripting (XSS) attacks. Unauthenticated users may exploit this weakness to perform state-changing actions on behalf of other users, potentially compromising the integrity of the site and the security of its users. The affected versions range from an unspecified version to 1.13. Website owners using this plugin should take immediate action to safeguard their installations.

Affected Version(s)

Navayan Subscribe <= 1.13

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien (Patchstack Alliance)
.
CVE-2025-53311 : Cross-Site Request Forgery in Navayan Subscribe by Amol Nirmala Waman