Description
Cross-Site Request Forgery (CSRF) vulnerability in Listings for Appfolio Listings for Appfolio listings-for-appfolio allows Stored XSS.This issue affects Listings for Appfolio: from n/a through <= 1.2.0.
Published: 2025-03-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stored cross‑site scripting vulnerability is triggered by a cross‑site request forgery flaw in the Listings for Appfolio WordPress plugin. Because the plugin accepts and saves form data without adequately validating the source, an attacker can submit a payload that is then rendered when site content is displayed, enabling script execution in the context of any user who views the affected page. The flaw corresponds to CWE‑352, a CSRF weakness that allows the injection of malicious content. The potential impact includes data theft, session hijacking, or site defacement for every user who accesses the vulnerable content.

Affected Systems

The issue affects WordPress installations running the Listings for Appfolio plugin version 1.2.0 or earlier. No further version detail is provided in the advisory, and the plugin is the only product identified as vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑severity vulnerability. With an EPSS score reported as less than 1% and the vulnerability not currently listed in CISA’s KEV catalog, the likelihood of exploitation is low at present, yet the potential damage remains significant. Attackers would typically leverage the CSRF flaw by tricking an authenticated user or a user with sufficient privileges into submitting malicious input, after which the stored payload would be executed globally. Since no official fix has been released at the time of this report, the risk persists until an update or mitigation is applied.

Generated by OpenCVE AI on May 1, 2026 at 12:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the plugin to the latest available version (>=1.3.0 if released).
  • Implement a robust CSRF token verification on all data‑modifying forms handled by the plugin.
  • Sanitize or encode all data stored by the plugin before rendering it on web pages to eliminate executed scripts.

Generated by OpenCVE AI on May 1, 2026 at 12:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8452 Cross-Site Request Forgery (CSRF) vulnerability in Deepak Khokhar Listings for Appfolio allows Stored XSS.This issue affects Listings for Appfolio: from n/a through 1.2.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Deepak Khokhar Listings for Appfolio allows Stored XSS.This issue affects Listings for Appfolio: from n/a through 1.2.0. Cross-Site Request Forgery (CSRF) vulnerability in Listings for Appfolio Listings for Appfolio listings-for-appfolio allows Stored XSS.This issue affects Listings for Appfolio: from n/a through <= 1.2.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 27 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Deepak Khokhar Listings for Appfolio allows Stored XSS.This issue affects Listings for Appfolio: from n/a through 1.2.0.
Title WordPress Listings for Appfolio plugin <= 1.2.0 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T23:56:13.159Z

Reserved: 2025-01-07T21:02:51.800Z

Link: CVE-2025-22658

cve-icon Vulnrichment

Updated: 2025-03-27T18:16:49.965Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T15:15:58.123

Modified: 2026-06-17T08:49:03.083

Link: CVE-2025-22658

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T12:45:15Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)