Description
Cross-Site Request Forgery (CSRF) vulnerability in ryscript WP Panoramio wp-panoramio allows Stored XSS.This issue affects WP Panoramio: from n/a through <= 1.5.0.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from a Cross‑Site Request Forgery flaw that allows an attacker to inject malicious scripts that are stored in the WordPress database. Once stored, these scripts execute whenever a page is rendered, compromising the integrity and confidentiality of the site and potentially exposing end‑user data. The vulnerability can lead to credential theft, session hijacking, or further exploitation of the WordPress installation.

Affected Systems

The WP Panoramio plugin from the ryscript vendor, all releases up to and including version 1.5.0, are affected. The issue lists coverage from the initial release through <=1.5.0 with no earlier baseline specified.

Risk and Exploitability

The CVSS score of 7.1 classifies the vulnerability as medium‑high severity. The EPSS score is below 1%, indicating a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a CSRF attack that requires a user interacting with a crafted link or form; because the payload is stored, no immediate user interaction after injection is required for the XSS to execute on other visitors.

Generated by OpenCVE AI on May 1, 2026 at 21:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Panoramio plugin to a version higher than 1.5.0 to eliminate the CSRF flaw.
  • If the plugin cannot be updated, disable or uninstall it to prevent the stored XSS vector.
  • Apply a web‑application firewall rule that blocks or sanitizes incoming POST requests to the plugin’s forms, thereby mitigating both CSRF and potential XSS injection.

Generated by OpenCVE AI on May 1, 2026 at 21:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3326 Cross-Site Request Forgery (CSRF) vulnerability in Ryan Sutana WP Panoramio allows Stored XSS.This issue affects WP Panoramio: from n/a through 1.5.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Ryan Sutana WP Panoramio allows Stored XSS.This issue affects WP Panoramio: from n/a through 1.5.0. Cross-Site Request Forgery (CSRF) vulnerability in ryscript WP Panoramio wp-panoramio allows Stored XSS.This issue affects WP Panoramio: from n/a through <= 1.5.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Sat, 18 Jan 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Ryan Sutana WP Panoramio allows Stored XSS.This issue affects WP Panoramio: from n/a through 1.5.0.
Title WordPress WP Panoramio plugin <= 1.5.0 - CSRF to Cross-Site Scripting vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T22:48:07.434Z

Reserved: 2025-01-16T11:27:59.220Z

Link: CVE-2025-23662

cve-icon Vulnrichment

Updated: 2025-01-17T17:20:35.484Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:43.167

Modified: 2026-06-17T08:56:11.563

Link: CVE-2025-23662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T21:15:25Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)