The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the pr_save_settings() function and insufficient input sanitization. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. The injected scripts will execute whenever a user accesses the plugin's settings page.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mahype
Mahype pagerank Tools Wordpress Wordpress wordpress |
|
| Vendors & Products |
Mahype
Mahype pagerank Tools Wordpress Wordpress wordpress |
Tue, 04 Nov 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the pr_save_settings() function and insufficient input sanitization. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. The injected scripts will execute whenever a user accesses the plugin's settings page. | |
| Title | Pagerank Tools <= 1.1.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-11-04T04:27:13.744Z
Reserved: 2025-10-28T15:45:10.914Z
Link: CVE-2025-12416
No data.
Status : Awaiting Analysis
Published: 2025-11-04T05:16:13.717
Modified: 2025-11-04T15:40:45.533
Link: CVE-2025-12416
No data.
OpenCVE Enrichment
Updated: 2025-11-04T16:33:05Z