Description
Cross-Site Request Forgery (CSRF) vulnerability in Dave Konopka UpDownUpDown updownupdown-postcomment-voting allows Stored XSS.This issue affects UpDownUpDown: from n/a through <= 1.1.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The UpDownUpDown WordPress plugin contains a cross‑site request forgery flaw that allows an attacker to submit a malicious payload through the voting interface. Because the request is accepted without verification of its origin, the payload is stored by the application and later executed in the browsers of site visitors, resulting in a stored cross‑site scripting vulnerability.

Affected Systems

All installations of the UpDownUpDown plugin from the initial release through version 1.1, developed by Dave Konopka, are affected. The flaw is present in every release in this range and can be triggered by any WordPress site that includes these plugin versions.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate severity, while the EPSS score of less than 1 % suggests a low probability of exploitation in the immediate future. The vulnerability is not listed in the CISA KEV catalog, implying no known large‑scale exploitation to date. The likely attack vector involves an adversary crafting a forged request to the voting endpoint, leveraging a user’s authenticated session to store the malicious script, which is then rendered when other users view the affected content.

Generated by OpenCVE AI on May 2, 2026 at 06:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the UpDownUpDown plugin to the latest version that removes the CSRF flaw.
  • If an update is not available, deactivate or delete the plugin to eliminate the attack surface.
  • Add a CSRF token or nonce to the voting form submissions so that only legitimate requests are processed.
  • Validate and escape all stored user input before rendering to prevent any residual cross‑site scripting.

Generated by OpenCVE AI on May 2, 2026 at 06:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3256 Cross-Site Request Forgery (CSRF) vulnerability in Dave Konopka, Martin Scharm UpDownUpDown allows Stored XSS.This issue affects UpDownUpDown: from n/a through 1.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Dave Konopka, Martin Scharm UpDownUpDown allows Stored XSS.This issue affects UpDownUpDown: from n/a through 1.1. Cross-Site Request Forgery (CSRF) vulnerability in Dave Konopka UpDownUpDown updownupdown-postcomment-voting allows Stored XSS.This issue affects UpDownUpDown: from n/a through <= 1.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Dave Konopka, Martin Scharm UpDownUpDown allows Stored XSS.This issue affects UpDownUpDown: from n/a through 1.1.
Title WordPress UpDownUpDown plugin <= 1.1 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:13.727Z

Reserved: 2025-01-16T11:26:29.090Z

Link: CVE-2025-23572

cve-icon Vulnrichment

Updated: 2025-01-17T17:21:27.985Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:40.403

Modified: 2026-04-23T15:24:04.263

Link: CVE-2025-23572

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T06:30:36Z

Weaknesses