Description
Cross-Site Request Forgery (CSRF) vulnerability in Rik Schennink Snippy snippy allows Reflected XSS.This issue affects Snippy: from n/a through <= 1.4.1.
Published: 2025-01-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cross‑Site Request Forgery in the Snippy WordPress plugin allows a user to submit a request that the plugin accepts without validating a CSRF token. The vulnerability can result in reflected XSS, where arbitrary JavaScript is rendered in the victim’s browser. The CVE description does not specify a particular HTTP endpoint, but it indicates that the absence of CSRF protection for plugin requests permits arbitrary payloads to be reflected back. The injected script runs with the privileges of the victim’s session, potentially hijacking cookies or defacing the site.

Affected Systems

All WordPress sites that use the Snippy plugin from any unreleased build up to and including version 1.4.1 are affected. No specific WordPress core or operating‑system version is mentioned in the CVE data, so any installation of the vulnerable plugin range is at risk.

Risk and Exploitability

The CVSS base score of 7.1 signifies a high severity issue. The EPSS score of less than 1% indicates that real‑world exploitation is currently unlikely, and the flaw is not listed in the CISA KEV catalog. Attackers would need to craft a request that bypasses CSRF checks, a scenario that is inferred from the description; the resulting reflected XSS could compromise confidentiality and integrity for users, especially administrators who could gain elevated access or deface the site.

Generated by OpenCVE AI on May 2, 2026 at 05:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Snippy plugin to a version newer than 1.4.1.
  • If an update is not yet available, temporarily deactivate or uninstall the Snippy plugin to eliminate the CSRF and XSS vectors.
  • Implement a site‑wide Content Security Policy that restricts inline scripts to provide additional protection against any residual XSS risk.

Generated by OpenCVE AI on May 2, 2026 at 05:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3435 Cross-Site Request Forgery (CSRF) vulnerability in PQINA Snippy allows Reflected XSS. This issue affects Snippy: from n/a through 1.4.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in PQINA Snippy allows Reflected XSS. This issue affects Snippy: from n/a through 1.4.1. Cross-Site Request Forgery (CSRF) vulnerability in Rik Schennink Snippy snippy allows Reflected XSS.This issue affects Snippy: from n/a through <= 1.4.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 23 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jan 2025 14:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in PQINA Snippy allows Reflected XSS. This issue affects Snippy: from n/a through 1.4.1.
Title WordPress Snippy Plugin <= 1.4.1 - CSRF to Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T23:05:20.222Z

Reserved: 2025-01-16T11:30:28.607Z

Link: CVE-2025-23803

cve-icon Vulnrichment

Updated: 2025-01-23T16:29:41.592Z

cve-icon NVD

Status : Deferred

Published: 2025-01-22T15:15:24.020

Modified: 2026-06-17T08:57:19.903

Link: CVE-2025-23803

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T05:45:20Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)