Description
Cross-Site Request Forgery (CSRF) vulnerability in cybio Floatbox Plus floatbox-plus allows Stored XSS.This issue affects Floatbox Plus: from n/a through <= 1.4.4.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Floatbox Plus plugin contains a Cross‑Site Request Forgery flaw (CWE‑352) that allows an attacker to submit a request as an authenticated user and force the plugin to store malicious JavaScript in the database. The stored script then executes in the browsers of all visitors who view the affected content, enabling theft of session data, defacement, or other malicious activity. The resulting Stored XSS undermines application integrity and potentially confidentiality of user data. The CVE documentation explicitly states the flaw leads to Stored XSS.

Affected Systems

WordPress sites using the cybio Floatbox Plus plugin, versions from the earliest available release up to and including 1.4.4. No other vendors or product variants are listed.

Risk and Exploitability

The vulnerability has a CVSS score of 7.1, categorizing it as High severity. This vulnerability is a Cross‑Site Request Forgery (CWE‑352). The EPSS score is less than 1 %, indicating a low probability of exploitation in the near term, and it is not present in the CISA KEV catalog. Exploitation requires an authenticated user to be tricked into sending a forged request—an attack vector that is commonly feasible through embedded links or emails (inferred). Because the flaw leads to persistent script injection rather than immediate remote code execution, the risk is bounded to browsers of site visitors, but it can still facilitate broad user compromise if the site serves many users.

Generated by OpenCVE AI on May 2, 2026 at 11:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Floatbox Plus plugin to the latest available version, which implements CSRF protection and sanitises stored content.
  • If the plugin is not essential, disable or uninstall it to eliminate the attack surface.
  • Review and cleanse the database for previously injected scripts, and configure a web application firewall to block further malicious code injections.

Generated by OpenCVE AI on May 2, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3287 Cross-Site Request Forgery (CSRF) vulnerability in Oliver Schaal Floatbox Plus allows Stored XSS.This issue affects Floatbox Plus: from n/a through 1.4.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Oliver Schaal Floatbox Plus allows Stored XSS.This issue affects Floatbox Plus: from n/a through 1.4.4. Cross-Site Request Forgery (CSRF) vulnerability in cybio Floatbox Plus floatbox-plus allows Stored XSS.This issue affects Floatbox Plus: from n/a through <= 1.4.4.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Oliver Schaal Floatbox Plus allows Stored XSS.This issue affects Floatbox Plus: from n/a through 1.4.4.
Title WordPress Floatbox Plus plugin <= 1.4.4 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:14.683Z

Reserved: 2025-01-16T11:27:15.896Z

Link: CVE-2025-23617

cve-icon Vulnrichment

Updated: 2025-01-17T17:21:13.780Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:41.027

Modified: 2026-06-17T08:55:49.920

Link: CVE-2025-23617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T11:30:41Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)