Description
Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer blighty-explorer allows Stored XSS.This issue affects Blightly Explorer: from n/a through <= 2.3.0.
Published: 2025-02-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability described is a Cross‑Site Request Forgery (CSRF) that allows an attacker to make a user’s browser store and later execute arbitrary JavaScript under the plugin’s context. Because the payload is stored – not just transiently injected – any visitor to the affected WordPress site, including logged‑in administrators, can be exposed to malicious code.

Affected Systems

Blighty Explorer plugin for WordPress, all releases up to and including version 2.3.0. Sites that have not upgraded beyond this version are susceptible, regardless of whether they are running the latest minor release prior to 2.3.0.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity condition. The EPSS score of less than 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, meaning there are no publicly documented exploits. The issue is that a CSRF flaw allows an attacker to store arbitrary JavaScript within the Blighty Explorer plugin, which will be executed when the site is accessed. This stored XSS can impact the confidentiality and integrity of the site by enabling code execution in the context of visitors and administrators, but the specific downstream effects depend on the injected payload and are not detailed in the CVE description.

Generated by OpenCVE AI on May 2, 2026 at 09:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install the latest version of Blighty Explorer from the official WordPress plugin repository; any release newer than 2.3.0 removes the vulnerability.
  • If an update cannot be applied at the moment, disable or delete the plugin from the WordPress installation to eliminate the attack vector.
  • Continuously monitor site logs for suspicious script injection attempts or unfamiliar code execution patterns.

Generated by OpenCVE AI on May 2, 2026 at 09:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4336 Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer allows Stored XSS. This issue affects Blightly Explorer: from n/a through 2.3.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer allows Stored XSS. This issue affects Blightly Explorer: from n/a through 2.3.0. Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer blighty-explorer allows Stored XSS.This issue affects Blightly Explorer: from n/a through <= 2.3.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Mon, 24 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Feb 2025 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer allows Stored XSS. This issue affects Blightly Explorer: from n/a through 2.3.0.
Title WordPress Blightly Explorer plugin <= 2.3.0 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:48.246Z

Reserved: 2025-02-21T16:45:40.233Z

Link: CVE-2025-27321

cve-icon Vulnrichment

Updated: 2025-02-24T15:47:46.657Z

cve-icon NVD

Status : Deferred

Published: 2025-02-24T15:15:17.753

Modified: 2026-06-17T09:03:23.883

Link: CVE-2025-27321

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T09:15:26Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)