Description
Cross-Site Request Forgery (CSRF) vulnerability in wptom All-In-One Cufon all-in-one-cufon allows Cross Site Request Forgery.This issue affects All-In-One Cufon: from n/a through <= 1.3.0.
Published: 2025-02-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to trigger malicious requests on behalf of a logged‑in WordPress administrator or privileged user. When the All‑In‑One Cufon plugin processes an unauthenticated request, it does not validate that the request originates from an intended source, which can cause unintended actions such as changing settings or executing privileged operations. The flaw aligns with CWE‑352 and risks integrity and availability of the WordPress site, but does not directly expose data or permit remote code execution.

Affected Systems

The flaw affects the WordPress All‑In‑One Cufon plugin, specifically versions from the legacy release through version 1.3.0. Administrators running these plugin versions on any WordPress installation are impacted.

Risk and Exploitability

With a CVSS score of 4.3 the vulnerability is of moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. However, because CSRF attacks can be launched from a harmless-looking site, the risk remains for users who remain logged in to an administrative session. The attack vector is inferred to be a malicious web page that tricks an authenticated user into navigating to a crafted URL that targets the plugin’s endpoint.

Generated by OpenCVE AI on May 1, 2026 at 15:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the All‑In‑One Cufon plugin to the latest released version (≥1.3.0).
  • If an update is not available, disable the plugin entirely to remove the vulnerable code path.
  • Add CSRF protection by ensuring all privileged plugin actions require a valid WordPress nonce, or install a security extension that enforces nonce checks on admin requests.

Generated by OpenCVE AI on May 1, 2026 at 15:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4343 Cross-Site Request Forgery (CSRF) vulnerability in wptom All-In-One Cufon allows Cross Site Request Forgery. This issue affects All-In-One Cufon: from n/a through 1.3.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in wptom All-In-One Cufon allows Cross Site Request Forgery. This issue affects All-In-One Cufon: from n/a through 1.3.0. Cross-Site Request Forgery (CSRF) vulnerability in wptom All-In-One Cufon all-in-one-cufon allows Cross Site Request Forgery.This issue affects All-In-One Cufon: from n/a through <= 1.3.0.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Mon, 24 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Feb 2025 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in wptom All-In-One Cufon allows Cross Site Request Forgery. This issue affects All-In-One Cufon: from n/a through 1.3.0.
Title WordPress All-In-One Cufon Plugin <= 1.3.0 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:47.983Z

Reserved: 2025-02-21T16:45:40.232Z

Link: CVE-2025-27315

cve-icon Vulnrichment

Updated: 2025-02-24T15:52:24.204Z

cve-icon NVD

Status : Deferred

Published: 2025-02-24T15:15:17.047

Modified: 2026-06-17T09:03:23.190

Link: CVE-2025-27315

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T16:00:16Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)