Description
Cross-Site Request Forgery (CSRF) vulnerability in mraliende URL-Preview-Box good-url-preview-box allows Cross Site Request Forgery.This issue affects URL-Preview-Box: from n/a through <= 1.20.
Published: 2025-02-07
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery flaw in the URL‑Preview‑Box plugin permits an unauthenticated attacker to execute a crafted request that stores a malicious payload in the plugin’s database entry. The stored script is then rendered in the browser of any user who views the affected content, leading to persistent cross‑site scripting. The vulnerability is rooted in deficient CSRF protection (CWE-352) and results in a stored malicious script that can compromise user sessions and data.

Affected Systems

The WordPress plugin URL‑Preview‑Box from the vendor mraliende is affected. All releases up to and including version 1.20 are vulnerable; no later version is listed as impacted.

Risk and Exploitability

The vulnerability’s CVSS score of 7.1 indicates a moderate to high risk. Although the EPSS score is less than 1‑% and the vulnerability is not listed in CISA’s KEV catalog, the exploit pathway requires only that an attacker convince a victim to follow a crafted link or submit a form that triggers the stored payload. Once in place, the stored XSS can run arbitrary JavaScript in the context of the site, potentially leading to credential theft or defacement. Given the simplicity of the CSRF trigger and the persistence of the XSS payload, the risk remains significant for sites that have not yet upgraded or mitigated the flaw.

Generated by OpenCVE AI on May 2, 2026 at 04:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the URL‑Preview‑Box plugin to the latest available version (1.21 or newer).
  • If an upgrade cannot be performed immediately, temporarily disable or uninstall the plugin to prevent further exploitation.
  • Review the plugin’s stored content and the site’s databases for any injected malicious scripts and remove them manually.

Generated by OpenCVE AI on May 2, 2026 at 04:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4034 Cross-Site Request Forgery (CSRF) vulnerability in mraliende URL-Preview-Box allows Cross Site Request Forgery. This issue affects URL-Preview-Box: from n/a through 1.20.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in mraliende URL-Preview-Box allows Cross Site Request Forgery. This issue affects URL-Preview-Box: from n/a through 1.20. Cross-Site Request Forgery (CSRF) vulnerability in mraliende URL-Preview-Box good-url-preview-box allows Cross Site Request Forgery.This issue affects URL-Preview-Box: from n/a through <= 1.20.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 07 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Feb 2025 10:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in mraliende URL-Preview-Box allows Cross Site Request Forgery. This issue affects URL-Preview-Box: from n/a through 1.20.
Title WordPress URL-Preview-Box plugin <= 1.20 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:35.535Z

Reserved: 2025-02-03T13:34:30.656Z

Link: CVE-2025-25104

cve-icon Vulnrichment

Updated: 2025-02-07T15:05:56.854Z

cve-icon NVD

Status : Deferred

Published: 2025-02-07T10:15:16.027

Modified: 2026-04-23T15:25:36.513

Link: CVE-2025-25104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T05:00:12Z

Weaknesses