Description
Cross-Site Request Forgery (CSRF) vulnerability in קידום ובניית אתרים add custom google tag manager add-custom-google-tag-manager allows Stored XSS.This issue affects add custom google tag manager: from n/a through <= 1.0.3.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cross‑Site Request Forgery in the add custom google tag manager plugin allows an attacker to bypass the normal request flow and inject JavaScript that is then stored in the site. The injected script will execute whenever page content is loaded by any visitor, which can lead to session theft, defacement or further compromise. The vulnerability stems from failure to verify the authenticity of administrative changes, creating a stored XSS vector.

Affected Systems

The affected product is the WordPress add custom google tag manager plugin for the קידום ובניית אתרים website builder. Every release up to version 1.0.3 is vulnerable; no newer versions are listed. Administrators who have not updated the plugin remain at risk unless the plugin is disabled.

Risk and Exploitability

The CVSS base score is 7.1, placing the issue in the high‑severity range, while the EPSS score of less than 1% indicates a currently low likelihood of exploitation. The flaw is not yet listed in CISA KEV catalog. Exploitation requires a user with administrative privileges or an authentication session to be present, as the flaw relies on cross‑site request forgery; however, a malicious site can lure a victim into submitting a crafted request that stores the script. Once inserted, the payload runs in the context of any user visiting the affected page, providing a persistent threat. The risk is mitigated by promptly applying a patch or removing the plugin.

Generated by OpenCVE AI on May 1, 2026 at 21:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the plugin to the latest version, which removes the CSRF bypass.
  • Disable the plugin or restrict its usage to administrators until the update is applied.
  • Add proper CSRF token validation to any form that modifies settings in WordPress, and sanitize all user input to prevent stored XSS.

Generated by OpenCVE AI on May 1, 2026 at 21:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3237 Cross-Site Request Forgery (CSRF) vulnerability in Oren hahiashvili add custom google tag manager allows Stored XSS.This issue affects add custom google tag manager: from n/a through 1.0.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Oren hahiashvili add custom google tag manager allows Stored XSS.This issue affects add custom google tag manager: from n/a through 1.0.3. Cross-Site Request Forgery (CSRF) vulnerability in קידום ובניית אתרים add custom google tag manager add-custom-google-tag-manager allows Stored XSS.This issue affects add custom google tag manager: from n/a through <= 1.0.3.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Oren hahiashvili add custom google tag manager allows Stored XSS.This issue affects add custom google tag manager: from n/a through 1.0.3.
Title WordPress add custom google tag manager plugin <= 1.0.3 - CSRF to Stored Cross-Site Scripting vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:12.729Z

Reserved: 2025-01-16T11:25:56.884Z

Link: CVE-2025-23537

cve-icon Vulnrichment

Updated: 2025-01-17T17:21:43.901Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:39.070

Modified: 2026-06-17T08:55:11.260

Link: CVE-2025-23537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T21:15:25Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)