Description
Cross-Site Request Forgery (CSRF) vulnerability in anmari amr personalise amr-personalise allows Cross Site Request Forgery.This issue affects amr personalise: from n/a through <= 2.10.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery (CWE-352) vulnerability exists in the anmari amr personalise WordPress plugin that enables an attacker to insert and store arbitrary JavaScript code into the site. The stored XSS payload executes in the browsers of anyone who visits affected pages, potentially leading to credential theft, session hijacking, defacement, or the delivery of additional malicious content. The vulnerability hinges on the ability to trick the server into processing a forged request without valid user tokens, which underscores the importance of proper CSRF mitigation.

Affected Systems

The flaw affects all installed instances of the anmari amr personalise plugin with a version number of 2.10 or earlier. The plugin is typically distributed through the WordPress Plugin Directory and can be found under the vendor name anmari. Users with the plugin enabled on their WordPress sites are at risk until the issue is remedied.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium to high severity, while the EPSS score of less than 1% suggests the probability of exploitation is currently low. However, the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the flaw is exploitable through a CSRF (CWE-352) attack, an attacker only needs to entice a legitimate user or an authenticated administrator to visit a crafted URL, making it relatively easy to achieve the stored XSS payload. The impact is confined to the affected site but can compromise all users who view the compromised content.

Generated by OpenCVE AI on May 2, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the amr personalise plugin to the latest available version that removes the CSRF to stored XSS flaw.
  • If an upgrade cannot be performed at short notice, temporarily deactivate or uninstall the plugin to eliminate the attack surface.
  • Ensure that any remaining form‑handling or content‑creation features on the site are protected with proper nonce or CSRF tokens, and verify that the plugin’s settings do not override these checks.

Generated by OpenCVE AI on May 2, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3500 Cross-Site Request Forgery (CSRF) vulnerability in anmari amr personalise allows Cross Site Request Forgery.This issue affects amr personalise: from n/a through 2.10.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in anmari amr personalise allows Cross Site Request Forgery.This issue affects amr personalise: from n/a through 2.10. Cross-Site Request Forgery (CSRF) vulnerability in anmari amr personalise amr-personalise allows Cross Site Request Forgery.This issue affects amr personalise: from n/a through <= 2.10.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in anmari amr personalise allows Cross Site Request Forgery.This issue affects amr personalise: from n/a through 2.10.
Title WordPress amr personalise plugin <= 2.10 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T22:44:13.111Z

Reserved: 2025-01-16T11:31:27.428Z

Link: CVE-2025-23880

cve-icon Vulnrichment

Updated: 2025-01-17T17:17:02.195Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T21:15:29.310

Modified: 2026-06-17T08:57:39.977

Link: CVE-2025-23880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T11:30:41Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)