Description
Cross-Site Request Forgery (CSRF) vulnerability in Shiv Prakash Tiwari WP Service Payment Form With Authorize.net wp-service-payment-form-with-authorizenet allows Reflected XSS.This issue affects WP Service Payment Form With Authorize.net: from n/a through <= 2.6.0.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a Cross‑Site Request Forgery that enables a reflected Cross‑Site Scripting attack. The WP Service Payment Form With Authorize.net plugin echoes data from a forged request back to the browser without proper sanitization. Based on the description, it is inferred that a malicious actor can craft a URL that, when clicked by a legitimate user, triggers the vulnerable flow and injects JavaScript into the response. The injected script executes in the victim’s browser context, creating a risk of credential theft, session hijacking, or defacement.

Affected Systems

The vulnerability impacts the WordPress plugin WP Service Payment Form With Authorize.net published by Shiv Prakash Tiwari. All releases up to and including version 2.6.0 are affected; newer versions are assumed to contain the fix.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity while the EPSS score of less than 1 % signals a low current exploitation probability. Attackers would typically entice a legitimate user to click a crafted link that triggers the plugin’s vulnerable flow. The reflected payload is executed only in the victim’s browser, so the impact is limited to the individual user’s session, but could lead to cookie theft, malicious redirects, or site defacement.

Generated by OpenCVE AI on May 2, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Service Payment Form With Authorize.net to a version newer than 2.6.0.
  • If the plugin must remain active, restrict its usage to authenticated administrators or disable public access to the payment form.
  • Deploy a content security policy that blocks execution of inline scripts to mitigate the impact of reflected XSS.

Generated by OpenCVE AI on May 2, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3436 Cross-Site Request Forgery (CSRF) vulnerability in Shiv Prakash Tiwari WP Service Payment Form With Authorize.net allows Reflected XSS.This issue affects WP Service Payment Form With Authorize.net: from n/a through 2.6.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Shiv Prakash Tiwari WP Service Payment Form With Authorize.net allows Reflected XSS.This issue affects WP Service Payment Form With Authorize.net: from n/a through 2.6.0. Cross-Site Request Forgery (CSRF) vulnerability in Shiv Prakash Tiwari WP Service Payment Form With Authorize.net wp-service-payment-form-with-authorizenet allows Reflected XSS.This issue affects WP Service Payment Form With Authorize.net: from n/a through <= 2.6.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Shiv Prakash Tiwari WP Service Payment Form With Authorize.net allows Reflected XSS.This issue affects WP Service Payment Form With Authorize.net: from n/a through 2.6.0.
Title WordPress WP Service Payment Form With Authorize.net Plugin <= 2.6.0 - CSRF to Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:20.752Z

Reserved: 2025-01-16T11:30:28.608Z

Link: CVE-2025-23804

cve-icon Vulnrichment

Updated: 2025-01-17T17:50:38.513Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T21:15:21.497

Modified: 2026-06-17T08:57:20.380

Link: CVE-2025-23804

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T11:30:41Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)