Description
Cross-Site Request Forgery (CSRF) vulnerability in sammyb WP Background Tile wp-background-tile allows Stored XSS.This issue affects WP Background Tile: from n/a through <= 1.0.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to store malicious JavaScript in the WP Background Tile plugin’s data through a Cross‑Site Request Forgery attack. Once stored, the script is rendered in the context of any visitor or administrator who loads the plugin, enabling actions such as credential theft, defacement, or arbitrary script execution. The weakness is a classic stored XSS exposed by circumvention of CSRF controls, leading to a loss of confidentiality and potential integrity and availability issues for the affected website.

Affected Systems

The WordPress plugin WP Background Tile from vendor sammyb is affected in all versions through 1.0. Each installation of this plugin, when using version 1.0 or earlier, is vulnerable until the issue is resolved. No further versions are known to be impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity, while the EPSS score of less than 1% suggests the likelihood of exploitation is low but not negligible. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to require a crafted HTTP request that leverages a missing CSRF token; an attacker would need to convince a privileged administrator to visit a malicious URL or supply a forged request. Once the request is processed, the injected script is persisted and will execute for all site users.

Generated by OpenCVE AI on May 1, 2026 at 21:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Background Tile to the latest available version (above 1.0) or apply any vendor‑supplied patch that removes the CSRF flaw.
  • If an update is not immediately feasible, disable the plugin or prevent it from loading until a fix is available.
  • Restrict the plugin’s settings page to trusted administrators and ensure a strong CSRF token validation mechanism is in place.

Generated by OpenCVE AI on May 1, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3257 Cross-Site Request Forgery (CSRF) vulnerability in Sam Burdge WP Background Tile allows Stored XSS.This issue affects WP Background Tile: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Sam Burdge WP Background Tile allows Stored XSS.This issue affects WP Background Tile: from n/a through 1.0. Cross-Site Request Forgery (CSRF) vulnerability in sammyb WP Background Tile wp-background-tile allows Stored XSS.This issue affects WP Background Tile: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Sam Burdge WP Background Tile allows Stored XSS.This issue affects WP Background Tile: from n/a through 1.0.
Title WordPress WP Background Tile plugin <= 1.0 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:13.699Z

Reserved: 2025-01-16T11:26:29.090Z

Link: CVE-2025-23573

cve-icon Vulnrichment

Updated: 2025-01-17T17:21:02.060Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:40.740

Modified: 2026-06-17T08:55:28.677

Link: CVE-2025-23573

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T21:15:25Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)