Description
Cross-Site Request Forgery (CSRF) vulnerability in hernanjh MercadoLibre Integration mercadolibre-integration allows Stored XSS.This issue affects MercadoLibre Integration: from n/a through <= 1.1.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a CSRF flaw that enables an attacker to store malicious JavaScript payloads in the MercadoLibre Integration plugin. When an authenticated user submits a forged request, the plugin records the payload. On subsequent visits to the relevant page the stored script executes in the victim’s browser, allowing data theft, session hijacking or defacement. The flaw is a cross‑site request forgery that results in stored XSS, classified as CWE‑352.

Affected Systems

Any WordPress site running the MercadoLibre Integration plugin version 1.1 or earlier is affected. The vendor listed is hernanjh. The issue resides solely in the WordPress plugin code and is independent of the underlying operating system.

Risk and Exploitability

The CVSS base score is 7.1, indicating moderate‑to‑high severity, but the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV database. Exploitation requires a legitimate user be tricked into submitting a forged request, so an attacker needs access to a user account capable of performing the vulnerable action. Once the payload is stored, all users who view the affected page are impacted, making the potential damage broad. Despite the low exploitation probability, the widespread cross‑site scripting risk warrants immediate remediation.

Generated by OpenCVE AI on May 1, 2026 at 21:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the MercadoLibre Integration plugin to a version newer than 1.1 that contains the fix.
  • If an immediate update is not available, disable the plugin until a patched version is released.
  • Restrict non‑admin users from executing the vulnerable form or implement an additional CSRF token check to block forged requests.

Generated by OpenCVE AI on May 1, 2026 at 21:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3323 Cross-Site Request Forgery (CSRF) vulnerability in Hernan Javier Hegykozi MercadoLibre Integration allows Stored XSS.This issue affects MercadoLibre Integration: from n/a through 1.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Hernan Javier Hegykozi MercadoLibre Integration allows Stored XSS.This issue affects MercadoLibre Integration: from n/a through 1.1. Cross-Site Request Forgery (CSRF) vulnerability in hernanjh MercadoLibre Integration mercadolibre-integration allows Stored XSS.This issue affects MercadoLibre Integration: from n/a through <= 1.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Hernan Javier Hegykozi MercadoLibre Integration allows Stored XSS.This issue affects MercadoLibre Integration: from n/a through 1.1.
Title WordPress MercadoLibre Integration plugin <= 1.1 - CSRF to Stored Cross-Site Scripting vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:16.252Z

Reserved: 2025-01-16T11:27:51.185Z

Link: CVE-2025-23659

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:42.750

Modified: 2026-06-17T08:56:10.147

Link: CVE-2025-23659

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T21:15:25Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)