Description
Cross-Site Request Forgery (CSRF) vulnerability in itmooti Theme My Ontraport Smartform theme-my-ontraport-smartform allows Stored XSS.This issue affects Theme My Ontraport Smartform: from n/a through <= 1.2.11.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery flaw in the Theme My Ontraport Smartform plugin enables attackers to inject malicious scripts that are stored in the database and later executed in browsers visiting the site. Such stored XSS can deface the site, steal session cookies, or steal user data, resulting in compromised confidentiality, integrity, and availability of the affected WordPress site. This weakness is a classic example of CWE‑352, which seeks to prevent unauthorized state‑changing requests.

Affected Systems

The vulnerability applies to the itmooti Theme My Ontraport Smartform plugin for WordPress, specifically every release from the initial version up to and including 1.2.11. No higher‑version patches were noted in the data, so any instance running 1.2.11 or earlier is affected.

Risk and Exploitability

The CVSS v3 score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation is currently rare. The vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation at this time. Exploitation requires a CSRF attack that results in a stored payload being saved to the database—likely achievable through a privileged user who can submit form content. If the site allows unprotected submissions, attackers may force this action without additional credentials by tricking an authenticated user in the browser.

Generated by OpenCVE AI on May 1, 2026 at 20:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Theme My Ontraport Smartform plugin to the latest secure version (if one exists beyond 1.2.11).
  • Verify that site-wide CSRF protection is enabled and that form submissions require a valid anti‑CSRF token.
  • If the plugin is not essential, consider disabling or removing it from the WordPress installation.

Generated by OpenCVE AI on May 1, 2026 at 20:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3368 Cross-Site Request Forgery (CSRF) vulnerability in ITMOOTI Theme My Ontraport Smartform allows Stored XSS.This issue affects Theme My Ontraport Smartform: from n/a through 1.2.11.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in ITMOOTI Theme My Ontraport Smartform allows Stored XSS.This issue affects Theme My Ontraport Smartform: from n/a through 1.2.11. Cross-Site Request Forgery (CSRF) vulnerability in itmooti Theme My Ontraport Smartform theme-my-ontraport-smartform allows Stored XSS.This issue affects Theme My Ontraport Smartform: from n/a through <= 1.2.11.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in ITMOOTI Theme My Ontraport Smartform allows Stored XSS.This issue affects Theme My Ontraport Smartform: from n/a through 1.2.11.
Title WordPress Theme My Ontraport Smartform plugin <= 1.2.11 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:17.943Z

Reserved: 2025-01-16T11:28:39.048Z

Link: CVE-2025-23717

cve-icon Vulnrichment

Updated: 2025-01-17T17:19:10.239Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:46.247

Modified: 2026-06-17T08:56:38.227

Link: CVE-2025-23717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T21:00:08Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)