Description
Cross-Site Request Forgery (CSRF) vulnerability in xavsio4 Visit Site Link enhanced visit-site-link-enhanced allows Stored XSS.This issue affects Visit Site Link enhanced: from n/a through <= 1.0.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A cross‑site request forgery flaw in the WordPress plugin Visit Site Link enhanced allows an attacker to inject arbitrary script that is stored within the site. The malicious script is persisted in the plugin’s database and executed whenever a site visitor loads a page that processes that stored input, thereby compromising the confidentiality and integrity of users’ browsers. This weakness is a CWE‑352, a Cross‑Site Request Forgery issue.

Affected Systems

The vulnerability affects the plugin published by xavsio4, titled Visit Site Link enhanced, in all releases from its initial version through version 1.0. Users running any of these versions are exposed.

Risk and Exploitability

With a CVSS score of 7.1 the flaw is considered moderate severity, but the EPSS score is reported below 1% and the vulnerability is not listed in CISA KEV, indicating low likelihood of widespread exploitation. Attackers would need to trigger the CSRF condition – for example by tricking an authenticated user or administrator into submitting a forged request – to embed the payload. Once stored, the payload runs in the context of any visitor, potentially enabling credential theft, session hijacking, or further propagation.

Generated by OpenCVE AI on May 2, 2026 at 09:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Visit Site Link enhanced to any version newer than 1.0, which contains the CSRF and XSS fix.
  • If an upgrade is not immediately feasible, disable or remove the plugin to eliminate the attack surface.
  • Apply strict input validation and sanitization in any remaining plugin settings, and ensure that future configurations incorporate robust CSRF protection.

Generated by OpenCVE AI on May 2, 2026 at 09:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3198 Cross-Site Request Forgery (CSRF) vulnerability in X Villamuera Visit Site Link enhanced allows Stored XSS.This issue affects Visit Site Link enhanced: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in X Villamuera Visit Site Link enhanced allows Stored XSS.This issue affects Visit Site Link enhanced: from n/a through 1.0. Cross-Site Request Forgery (CSRF) vulnerability in xavsio4 Visit Site Link enhanced visit-site-link-enhanced allows Stored XSS.This issue affects Visit Site Link enhanced: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in X Villamuera Visit Site Link enhanced allows Stored XSS.This issue affects Visit Site Link enhanced: from n/a through 1.0.
Title WordPress Visit Site Link enhanced plugin <= 1.0 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:09.996Z

Reserved: 2025-01-16T11:25:03.614Z

Link: CVE-2025-23470

cve-icon Vulnrichment

Updated: 2025-01-17T17:23:04.012Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:36.700

Modified: 2026-06-17T08:54:37.640

Link: CVE-2025-23470

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T10:00:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)