Description
Cross-Site Request Forgery (CSRF) vulnerability in Stargazer WP-BlackCheck wp-blackcheck allows Stored XSS.This issue affects WP-BlackCheck: from n/a through <= 2.7.2.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The likely attack vector, inferred from the description, is a forged request originating from an external entity, such as a user clicking a malicious link. The vulnerability is a Cross‑Site Request Forgery that allows an attacker to inject a persistent script into the WP‑BlackCheck plugin’s data store. Once stored, the malicious script executes in the browser of any user who views the affected content, potentially stealing authentication cookies, session data, or defacing the site. The weakness is identified as CWE‑352, indicating improper validation of input originating from a request that is forged by an external entity.

Affected Systems

WordPress plugin Stargazer WP‑BlackCheck, versions up to and including 2.7.2. Any WordPress site running a vulnerable instance of this plugin is at risk.

Risk and Exploitability

The likely attack vector, based on the description, is forging a legitimate‑looking request – for example by having a user visit a malicious link – that triggers the stored script. The CVSS score of 7.1 conveys a high likelihood of exploitation and significant impact. The EPSS score is below 1%, suggesting that while exploitation is technically possible, it is unlikely to be widespread at present. The vulnerability is not listed in the CISA KEV catalog. Once injected, the stored XSS can affect all site visitors, bypassing the same‑origin policy.

Generated by OpenCVE AI on May 2, 2026 at 09:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest WP‑BlackCheck plugin version (>= 2.7.3) to remove the vulnerability.
  • If an upgrade is not immediately possible, uninstall or disable the WP‑BlackCheck plugin until a patch is available.
  • Implement site‑wide CSRF protection (e.g., activate a security plugin that validates nonce tokens) to mitigate the risk of forged requests.

Generated by OpenCVE AI on May 2, 2026 at 09:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3221 Cross-Site Request Forgery (CSRF) vulnerability in Viktoria Rei Bauer WP-BlackCheck allows Stored XSS.This issue affects WP-BlackCheck: from n/a through 2.7.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Viktoria Rei Bauer WP-BlackCheck allows Stored XSS.This issue affects WP-BlackCheck: from n/a through 2.7.2. Cross-Site Request Forgery (CSRF) vulnerability in Stargazer WP-BlackCheck wp-blackcheck allows Stored XSS.This issue affects WP-BlackCheck: from n/a through <= 2.7.2.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Sat, 18 Jan 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Viktoria Rei Bauer WP-BlackCheck allows Stored XSS.This issue affects WP-BlackCheck: from n/a through 2.7.2.
Title WordPress WP-BlackCheck plugin <= 2.7.2 - CSRF to Stored Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:10.968Z

Reserved: 2025-01-16T11:25:35.344Z

Link: CVE-2025-23511

cve-icon Vulnrichment

Updated: 2025-01-17T17:21:49.924Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:38.040

Modified: 2026-06-17T08:54:57.347

Link: CVE-2025-23511

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T10:00:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)