Description
Cross-Site Request Forgery (CSRF) vulnerability in Optimal Access KBucket kbucket allows Stored XSS.This issue affects KBucket: from n/a through <= 4.1.6.
Published: 2025-01-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The KBucket plugin for WordPress allows an attacker to perform a Cross‑Site Request Forgery (CSRF) attack. By convincing an authenticated administrator to visit a crafted URL, the attacker can inject arbitrary JavaScript that is then stored in the site’s database. When the compromised content is later rendered in the browser, the malicious script executes with the privileges of the site visitor, potentially leading to session hijacking, defacement, or the execution of further malicious code. This stored XSS flaw is defined as CWE‑352.

Affected Systems

The vulnerability exists in the Optimal Access KBucket plugin (WordPress) for all versions up to and including 4.1.6. Any WordPress site running a vulnerable version of this plugin is susceptible.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, indicating a high severity level. The EPSS score is less than 1%, suggesting that the likelihood of exploitation in the wild is currently low. It is not listed in the CISA KEV catalog. Attackers would need access to an authenticated admin session or the ability to trick an admin into visiting the forged request, a condition that is relatively easy to achieve in social engineering or compromised accounts scenarios. Once the payload is stored, any visitor who loads the affected content will be exposed to the malicious JavaScript.

Generated by OpenCVE AI on May 1, 2026 at 18:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the KBucket plugin to the latest version available from the official WordPress repository.
  • Clear any cached pages or objects that may have retained the vulnerable content after the update.
  • Review site content for any previously injected scripts and remove them manually or via a cleanup script.

Generated by OpenCVE AI on May 1, 2026 at 18:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3770 Cross-Site Request Forgery (CSRF) vulnerability in Optimal Access Inc. KBucket allows Stored XSS. This issue affects KBucket: from n/a through 4.1.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Optimal Access Inc. KBucket allows Stored XSS. This issue affects KBucket: from n/a through 4.1.6. Cross-Site Request Forgery (CSRF) vulnerability in Optimal Access KBucket kbucket allows Stored XSS.This issue affects KBucket: from n/a through <= 4.1.6.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 24 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Optimal Access Inc. KBucket allows Stored XSS. This issue affects KBucket: from n/a through 4.1.6.
Title WordPress KBucket plugin <= 4.1.6 - CSRF to Stored Cross-Site Scripting vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:28.493Z

Reserved: 2025-01-23T14:50:25.794Z

Link: CVE-2025-24562

cve-icon Vulnrichment

Updated: 2025-01-24T18:47:27.739Z

cve-icon NVD

Status : Deferred

Published: 2025-01-24T18:15:33.810

Modified: 2026-06-17T08:59:13.977

Link: CVE-2025-24562

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T19:00:08Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)