Description
Cross-Site Request Forgery (CSRF) vulnerability in tubepress TubePress.NET tubepressnet allows Cross Site Request Forgery.This issue affects TubePress.NET: from n/a through <= 4.0.1.
Published: 2025-01-07
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a CSRF flaw in the TubePress.NET WordPress plugin, which can be exploited by an attacker to forge requests that inject malicious script into stored content. Attackers can create a request that, when executed by an authenticated user, results in stored cross‑site scripting that subsequently runs in visitors’ browsers, potentially compromising confidentiality, integrity and availability of the site.

Affected Systems

All installations of the TubePress.NET plugin from the earliest released version through version 4.0.1 are affected. The plugin is distributed by tubepress:TubePress.NET and is commonly used in WordPress sites that embed video content.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability poses a moderate to high risk. The EPSS score of less than 1% indicates the likelihood of exploitation is low at the current time, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a CSRF attack, which generally requires an authenticated user interaction, such as a logged‑in administrator visiting a crafted link.

Generated by OpenCVE AI on May 1, 2026 at 22:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade TubePress.NET to the latest version (≥4.0.2) to remove the CSRF and stored XSS flaw.
  • If an immediate upgrade is not possible, disable or uninstall the plugin until a patch is available.
  • Add site‑wide CSRF protection by installing a reputable security plugin that enforces CSRF tokens for all sensitive actions.

Generated by OpenCVE AI on May 1, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2837 Cross-Site Request Forgery (CSRF) vulnerability in Mario Mansour and Geoff Peters TubePress.NET allows Cross Site Request Forgery.This issue affects TubePress.NET: from n/a through 4.0.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Mario Mansour and Geoff Peters TubePress.NET allows Cross Site Request Forgery.This issue affects TubePress.NET: from n/a through 4.0.1. Cross-Site Request Forgery (CSRF) vulnerability in tubepress TubePress.NET tubepressnet allows Cross Site Request Forgery.This issue affects TubePress.NET: from n/a through <= 4.0.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 08 Jan 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jan 2025 15:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Mario Mansour and Geoff Peters TubePress.NET allows Cross Site Request Forgery.This issue affects TubePress.NET: from n/a through 4.0.1.
Title WordPress TubePress.NET Plugin <= 4.0.1 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:01.586Z

Reserved: 2025-01-07T10:23:24.211Z

Link: CVE-2025-22559

cve-icon Vulnrichment

Updated: 2025-01-07T16:20:32.980Z

cve-icon NVD

Status : Deferred

Published: 2025-01-07T16:15:52.243

Modified: 2026-06-17T08:48:16.147

Link: CVE-2025-22559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T22:30:16Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)