Description
Cross-Site Request Forgery (CSRF) vulnerability in Master Software Solutions WP VTiger Synchronization msstiger allows Stored XSS.This issue affects WP VTiger Synchronization: from n/a through <= 1.1.1.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cross‑Site Request Forgery in the WP VTiger Synchronization plugin permits an attacker to store malicious HTML and JavaScript in the plugin’s configuration, leading to a stored XSS vulnerability. The flaw allows arbitrary script execution in the browsers of users who view the affected content, potentially leaking session cookies or performing other malicious actions. The weakness corresponds to CWE‑352, a CSRF flaw that neglects proper verification and sanitization of incoming data. The impact manifests as confidentiality breaches, integrity violations, and the risk of defacement or spreading malware to all visitors of the infected site.

Affected Systems

The vulnerability affects the Master Software Solutions WP VTiger Synchronization WordPress plugin, specifically versions up to and including 1.1.1. Any installation of this plugin, regardless of the WordPress core version, is susceptible. Administrators who have edited the plugin settings without proper CSRF checks fall under the impacted scope.

Risk and Exploitability

With a CVSS score of 7.1 the flaw is considered high severity, yet the EPSS score of <1% suggests exploitation is currently unlikely but still possible in targeted attacks. The flaw is not listed in CISA’s KEV catalog, indicating no mass exploitation is reported. The likely attack path is a CSRF request originating from an external site that a logged‑in administrator inadvertently visits, or from social‑engineering phishing. Successful exploitation would enable persistent, arbitrary script execution on the victim site, with a wide attack surface due to the plugin’s storage of user‑supplied data.

Generated by OpenCVE AI on May 1, 2026 at 21:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest version of WP VTiger Synchronization (>=1.1.2) or uninstall the vulnerable plugin entirely.
  • Sanitize any existing data stored by the plugin by reviewing configuration entries and removing injected scripts.
  • Ensure the site uses a robust CSRF protection mechanism (e.g., a nonce or token system) and restrict the plugin’s configuration pages to administrators only.
  • Consider implementing a Web Application Firewall or a security plugin that detects and blocks XSS payloads.

Generated by OpenCVE AI on May 1, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3191 Cross-Site Request Forgery (CSRF) vulnerability in mastersoftwaresolutions WP VTiger Synchronization allows Stored XSS.This issue affects WP VTiger Synchronization: from n/a through 1.1.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in mastersoftwaresolutions WP VTiger Synchronization allows Stored XSS.This issue affects WP VTiger Synchronization: from n/a through 1.1.1. Cross-Site Request Forgery (CSRF) vulnerability in Master Software Solutions WP VTiger Synchronization msstiger allows Stored XSS.This issue affects WP VTiger Synchronization: from n/a through <= 1.1.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in mastersoftwaresolutions WP VTiger Synchronization allows Stored XSS.This issue affects WP VTiger Synchronization: from n/a through 1.1.1.
Title WordPress WP VTiger Synchronization plugin <= 1.1.1 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:09.886Z

Reserved: 2025-01-16T11:24:55.799Z

Link: CVE-2025-23455

cve-icon Vulnrichment

Updated: 2025-01-17T17:22:38.040Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:36.033

Modified: 2026-06-17T08:54:30.530

Link: CVE-2025-23455

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T21:30:15Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)