Description
Cross-Site Request Forgery (CSRF) vulnerability in DSmidge HTTP to HTTPS link changer by Eyga.net https-links-in-content allows Stored XSS.This issue affects HTTP to HTTPS link changer by Eyga.net: from n/a through <= 0.2.4.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery flaw in the DSmidge HTTP to HTTPS link changer by Eyga.net allows an attacker who can trick an authenticated administrator into issuing a request to the WordPress site to inject arbitrary JavaScript. The malicious code is stored in the content database and executed for every user who views the affected page, providing a persistent attack surface for session hijacking, data theft, or defacement. The weakness is a classic CSRF that results in Stored XSS, making the potential impact severe for the confidentiality and integrity of site content and the browsing session of all visitors.

Affected Systems

WordPress installations that have installed the DSmidge HTTP to HTTPS link changer by Eyga.net plugin at any version up to 0.2.4. No specific PHP or server levels are required; the vulnerability exists solely in the plugin code when enabled on a WordPress site.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability is considered High severity. The EPSS score of less than 1% indicates a very low current likelihood of automated exploitation, and the issue is not listed in CISA's KEV catalog. However, because the vector is CSRF, a determined attacker who can target site administrators or users with active sessions can still achieve the stored XSS payload. The attack does not require privileged access to the filesystem; it simply needs the ability to generate a forged request, which can often be delivered via malicious emails or compromised sites.

Generated by OpenCVE AI on May 1, 2026 at 21:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the DSmidge plugin to the latest available version (>= 0.2.5) which removes the vulnerable CSRF handling.
  • If an upgrade is not immediately possible, temporarily disable or remove the plugin from the site to prevent persistence of the stored payloads.
  • Restrict administrative access to HTTPS only and ensure that all administrator credentials are unique, strong, and not cached or reused across sites to reduce the risk of CSRF instrumentation.

Generated by OpenCVE AI on May 1, 2026 at 21:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3336 Cross-Site Request Forgery (CSRF) vulnerability in DSmidgy HTTP to HTTPS link changer by Eyga.net allows Stored XSS.This issue affects HTTP to HTTPS link changer by Eyga.net: from n/a through 0.2.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in DSmidgy HTTP to HTTPS link changer by Eyga.net allows Stored XSS.This issue affects HTTP to HTTPS link changer by Eyga.net: from n/a through 0.2.4. Cross-Site Request Forgery (CSRF) vulnerability in DSmidge HTTP to HTTPS link changer by Eyga.net https-links-in-content allows Stored XSS.This issue affects HTTP to HTTPS link changer by Eyga.net: from n/a through <= 0.2.4.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in DSmidgy HTTP to HTTPS link changer by Eyga.net allows Stored XSS.This issue affects HTTP to HTTPS link changer by Eyga.net: from n/a through 0.2.4.
Title WordPress HTTP to HTTPS link changer by Eyga.net plugin <= 0.2.4 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:16.915Z

Reserved: 2025-01-16T11:28:07.195Z

Link: CVE-2025-23677

cve-icon Vulnrichment

Updated: 2025-01-17T17:19:58.597Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:43.900

Modified: 2026-06-17T08:56:18.827

Link: CVE-2025-23677

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T21:15:25Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)