Description
Cross-Site Request Forgery (CSRF) vulnerability in Real Seguro Viagem Real Seguro Viagem seguro-viagem allows Stored XSS.This issue affects Real Seguro Viagem: from n/a through <= 2.0.5.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Real Seguro Viagem plugin for WordPress contains a CSRF flaw that permits an attacker to submit a forged request to the site’s backend. Because of this, the attacker can force the plugin to store user‑supplied input. The stored data is later rendered without proper escaping, leading to a stored cross‑site scripting (XSS) vulnerability. An attacker who succeeds can inject arbitrary JavaScript that will run in the browsers of any visitor who accesses pages that display the injected content, enabling session hijacking, defacement, or distribution of malware.

Affected Systems

The flaw affects all releases of Real Seguro Viagem up to and including version 2.0.5. The plugin is available for installation in WordPress sites that accept it from the WordPress.org repository or other sources. No specific operating system or web server is required beyond standard WordPress hosting.

Risk and Exploitability

The CVSS base score is 7.1, reflecting moderate severity. The EPSS score of less than 1 percent indicates a low probability that the vulnerability has been actively exploited yet. The vulnerability is not listed in the CISA KEV catalog. The attack would require the attacker to lure a privileged user or server to send a crafted request, utilizing CSRF, thereby making the primary attack vector likely remote through a web browser or automated script. Once the XSS code is stored, any visitor to the affected content could be impacted. Given the low EPSS, exploitation is not yet widespread, but the impact could be severe if an attacker were to inject malicious content.

Generated by OpenCVE AI on May 1, 2026 at 21:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Real Seguro Viagem plugin to the latest available version (any release newer than 2.0.5).
  • If the plugin is no longer needed, uninstall or deactivate it entirely.
  • Audit the site’s stored content for any injected JavaScript and remove or sanitize it; run a security scan to confirm no malicious payloads remain.
  • Implement additional CSRF protection in the WordPress installation, such as ensuring form requests include non‑ces, to reduce the risk of similar attacks in other plugins.

Generated by OpenCVE AI on May 1, 2026 at 21:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3327 Cross-Site Request Forgery (CSRF) vulnerability in Real Seguro Viagem Real Seguro Viagem allows Stored XSS.This issue affects Real Seguro Viagem: from n/a through 2.0.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Real Seguro Viagem Real Seguro Viagem allows Stored XSS.This issue affects Real Seguro Viagem: from n/a through 2.0.5. Cross-Site Request Forgery (CSRF) vulnerability in Real Seguro Viagem Real Seguro Viagem seguro-viagem allows Stored XSS.This issue affects Real Seguro Viagem: from n/a through <= 2.0.5.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Real Seguro Viagem Real Seguro Viagem allows Stored XSS.This issue affects Real Seguro Viagem: from n/a through 2.0.5.
Title WordPress Real Seguro Viagem plugin <= 2.0.5 - CSRF to Stored Cross-Site Scripting vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:16.304Z

Reserved: 2025-01-16T11:27:59.220Z

Link: CVE-2025-23664

cve-icon Vulnrichment

Updated: 2025-01-17T17:20:28.336Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:43.320

Modified: 2026-06-17T08:56:12.647

Link: CVE-2025-23664

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T21:15:25Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)