Description
Cross-Site Request Forgery (CSRF) vulnerability in IT-RAYS RAYS Grid rays-grid allows Cross Site Request Forgery.This issue affects RAYS Grid: from n/a through <= 1.3.1.
Published: 2025-02-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a classic Cross‑Site Request Forgery flaw that allows an attacker to submit actions on behalf of an authenticated WordPress user who has the RAYS Grid plugin installed. The flaw does not provide direct code execution or privilege escalation, but it permits any state‑changing action that the legitimate user can perform within the plugin, potentially altering page layout, schedule or deleting content. The weakness is identified as CWE‑352. The impact is limited to the permissions of the victim user and requires that the victim be logged into the site and have the plugin active during the attack.

Affected Systems

The vulnerability affects the WordPress plugin RAYS Grid from IT‑RAYS, versions up to and including 1.3.1. All releases from the earliest to 1.3.1 contain the flaw. Affected hosts are any WordPress installations that have the RAYS Grid plugin present and are using a version ≤1.3.1.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium severity. The EPSS score of less than 1% suggests that exploitation events are very rare, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need the victim user to be authenticated and to visit a malicious site that issues forged requests targeting the plugin endpoints. No network‑level exploit is required, so the attack vector is largely user‑side and is influenced by user behavior. Overall risk is moderate if the plugin is widely used but the likelihood of exploitation remains low.

Generated by OpenCVE AI on May 1, 2026 at 15:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update RAYS Grid to version 1.3.2 or later to remove the CSRF flaw
  • If an upgrade is not immediately possible, remove or deactivate the RAYS Grid plugin to eliminate the attack surface
  • Implement a site‑wide CSRF protection mechanism, such as a security plugin that enforces token validation for all POST requests

Generated by OpenCVE AI on May 1, 2026 at 15:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4347 Cross-Site Request Forgery (CSRF) vulnerability in IT-RAYS RAYS Grid allows Cross Site Request Forgery. This issue affects RAYS Grid: from n/a through 1.3.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in IT-RAYS RAYS Grid allows Cross Site Request Forgery. This issue affects RAYS Grid: from n/a through 1.3.1. Cross-Site Request Forgery (CSRF) vulnerability in IT-RAYS RAYS Grid rays-grid allows Cross Site Request Forgery.This issue affects RAYS Grid: from n/a through <= 1.3.1.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 25 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Feb 2025 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in IT-RAYS RAYS Grid allows Cross Site Request Forgery. This issue affects RAYS Grid: from n/a through 1.3.1.
Title WordPress RAYS Grid Plugin <= 1.3.1 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

It-rays Rays Grid
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:48.174Z

Reserved: 2025-02-21T16:45:40.232Z

Link: CVE-2025-27317

cve-icon Vulnrichment

Updated: 2025-02-24T15:49:37.144Z

cve-icon NVD

Status : Deferred

Published: 2025-02-24T15:15:17.353

Modified: 2026-04-23T15:26:21.590

Link: CVE-2025-27317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T15:45:16Z

Weaknesses