Description
Cross-Site Request Forgery (CSRF) vulnerability in njshofe Smoothness Slider Shortcode smoothness-slider-shortcode allows Cross Site Request Forgery.This issue affects Smoothness Slider Shortcode: from n/a through <= v1.2.2.
Published: 2025-01-07
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery (CSRF) flaw in the Smoothness Slider Shortcode plugin for WordPress versions 1.2.2 and earlier. An attacker who can cause a victim to visit a specially crafted URL can force the victim’s authenticated browser to perform actions with the plugin’s privileges. Because the CSRF can trigger the storage of malicious scripts, the vulnerability can lead to stored cross‑site scripting that affects all visitors. If the plugin allows content creation or modification, the attacker may alter site content or configuration, potentially enabling further attacks such as phishing or defacement. The flaw is identified as CWE‑352.

Affected Systems

WordPress sites running the Smoothness Slider Shortcode plugin from version 1.2.2 down to the lowest released version. The vendor is njshofe, and the product is Smoothness Slider Shortcode. All versions labeled 1.2.2 or older are affected; no later versions are listed.

Risk and Exploitability

The CVSS score of 7.1 classifies the flaw as high severity, while the EPSS score of <1% indicates a low overall exploitation likelihood at present. It is not listed in the CISA KEV catalog, reducing immediate threat visibility. The likely attack vector involves a malicious site issuing a forged request that leverages the victim’s authenticated session. Because the flaw does not require authentication on the attacker’s part, an outsider can exploit it simply by enticing an admin to visit a malicious link. In environments where there are users with elevated privileges or the plugin is exposed to public interfaces, the risk becomes more pronounced.

Generated by OpenCVE AI on May 2, 2026 at 06:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Smoothness Slider Shortcode plugin to a version newer than 1.2.2, or delete it if not required.
  • If upgrading is not immediately possible, restrict the plugin’s admin endpoints to authenticated users only and block unauthenticated requests.
  • Add nonce verification or referer checks to the plugin’s state‑changing actions to mitigate CSRF.

Generated by OpenCVE AI on May 2, 2026 at 06:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2833 Cross-Site Request Forgery (CSRF) vulnerability in Noel Jarencio. Smoothness Slider Shortcode allows Cross Site Request Forgery.This issue affects Smoothness Slider Shortcode: from n/a through v1.2.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Noel Jarencio. Smoothness Slider Shortcode allows Cross Site Request Forgery.This issue affects Smoothness Slider Shortcode: from n/a through v1.2.2. Cross-Site Request Forgery (CSRF) vulnerability in njshofe Smoothness Slider Shortcode smoothness-slider-shortcode allows Cross Site Request Forgery.This issue affects Smoothness Slider Shortcode: from n/a through <= v1.2.2.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 07 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jan 2025 15:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Noel Jarencio. Smoothness Slider Shortcode allows Cross Site Request Forgery.This issue affects Smoothness Slider Shortcode: from n/a through v1.2.2.
Title WordPress Smoothness Slider Shortcode plugin <= v1.2.2 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:01.636Z

Reserved: 2025-01-07T10:23:17.404Z

Link: CVE-2025-22555

cve-icon Vulnrichment

Updated: 2025-01-07T16:32:48.808Z

cve-icon NVD

Status : Deferred

Published: 2025-01-07T16:15:51.627

Modified: 2026-06-17T08:48:14.270

Link: CVE-2025-22555

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T07:00:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)