Description
Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Turcu Auto FTP auto-ftp allows Stored XSS.This issue affects Auto FTP: from n/a through <= 1.0.1.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to inject arbitrary scripts into the website’s stored data. When an authenticated user submits a form under the attacker’s guidance, malicious JavaScript can be written into the site’s content, enabling persistent cross‑site scripting that can steal user credentials, modify page content, and deface the site.

Affected Systems

The issue affects the WordPress Auto FTP plugin developed by Ciprian Turcu. All released versions through 1.0.1 are vulnerable; the wording "from n/a through <= 1.0.1" indicates that any install prior to or including 1.0.1 is at risk.

Risk and Exploitability

With a CVSS score of 7.1, the flaw is considered medium‑to‑high severity. The EPSS score of less than 1 % indicates a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack path relies on a CSRF vector, requiring the attacker to coerce an authenticated user, typically an administrator, into submitting a crafted request that stores malicious script code. Once stored, the script executes in the context of any visitor to the affected content, enabling theft of session cookies, defacement, and further lateral movement.

Generated by OpenCVE AI on May 1, 2026 at 20:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Auto FTP plugin to the latest release that addresses the CSRF vulnerability.
  • If an update is not immediately possible, disable the plugin or restrict its use to trusted administrators only to limit the window of exploitation.
  • Inspect the site’s stored content for malicious scripts introduced through this flaw and remove or sanitize them, then enable web‑application firewall rules to block similar injection attempts.

Generated by OpenCVE AI on May 1, 2026 at 20:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3425 Cross-Site Request Forgery (CSRF) vulnerability in Turcu Ciprian Auto FTP allows Stored XSS. This issue affects Auto FTP: from n/a through 1.0.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Turcu Ciprian Auto FTP allows Stored XSS. This issue affects Auto FTP: from n/a through 1.0.1. Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Turcu Auto FTP auto-ftp allows Stored XSS.This issue affects Auto FTP: from n/a through <= 1.0.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Turcu Ciprian Auto FTP allows Stored XSS. This issue affects Auto FTP: from n/a through 1.0.1.
Title WordPress Auto FTP plugin <= 1.0.1 - CSRF to Stored Cross-Site Scripting vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T22:48:57.053Z

Reserved: 2025-01-16T11:30:21.146Z

Link: CVE-2025-23793

cve-icon Vulnrichment

Updated: 2025-01-17T17:30:59.316Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T21:15:20.267

Modified: 2026-06-17T08:57:15.140

Link: CVE-2025-23793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T20:15:24Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)