Description
Cross-Site Request Forgery (CSRF) vulnerability in Pascal Casier Board Election board-election allows Stored XSS.This issue affects Board Election: from n/a through <= 1.0.1.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Board Election plugin contains a cross‑site request forgery flaw that lets an attacker force an authenticated user to submit a malicious request, which the plugin then stores as a user‑controlled script. When other users later view the stored content, the script executes in their browsers, leading to potential defacement, credential theft, or session hijacking. This stored XSS capability compromises confidentiality and integrity on the affected site.

Affected Systems

The vulnerability affects Pascal Casier's WordPress Board Election plugin for versions from inception through 1.0.1 inclusive. Any WordPress installation running an affected version should be verified.

Risk and Exploitability

Based on the description, it is inferred that the attack vector involves an attacker prompting a legitimate site user to submit a malicious request, which the plugin then stores as cross‑site scripting. The CVSS score of 7.1 classifies the issue as high severity, and an EPSS score of less than 1% suggests a low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. Nonetheless, this exploitation path requires only that a legitimate site user be tricked into submitting a request, a condition that is easy for an attacker to achieve in a targeted attack. Administrators should treat this as a high‑risk condition until mitigated.

Generated by OpenCVE AI on May 2, 2026 at 06:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Board Election plugin to version 1.0.2 or later
  • If the plugin cannot be updated, remove the Board Election plugin from the WordPress installation
  • Employ strong passwords for all administrative accounts and limit the number of users with permission to edit the plugin

Generated by OpenCVE AI on May 2, 2026 at 06:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3212 Cross-Site Request Forgery (CSRF) vulnerability in Pascal Casier Board Election allows Stored XSS.This issue affects Board Election: from n/a through 1.0.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Pascal Casier Board Election allows Stored XSS.This issue affects Board Election: from n/a through 1.0.1. Cross-Site Request Forgery (CSRF) vulnerability in Pascal Casier Board Election board-election allows Stored XSS.This issue affects Board Election: from n/a through <= 1.0.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Pascal Casier Board Election allows Stored XSS.This issue affects Board Election: from n/a through 1.0.1.
Title WordPress Board Election plugin <= 1.0.1 - CSRF to Stored Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:10.851Z

Reserved: 2025-01-16T11:25:26.988Z

Link: CVE-2025-23499

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:37.440

Modified: 2026-06-17T08:54:51.660

Link: CVE-2025-23499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T06:30:36Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)