Description
Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover remove-date-and-gravatar-under-comment allows Cross Site Request Forgery.This issue affects Comment Date and Gravatar remover: from n/a through <= 1.0.
Published: 2025-03-11
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw that allows a malicious actor to trigger actions within the Comment Date and Gravatar remover plugin using the credentials of an authenticated WordPress user. The plugin would then modify or delete comment timestamps and gravatar images without the user’s knowledge, potentially corrupting the comment timeline or compromising user identity displays. The flaw does not provide direct access to the site or data beyond the actions the user is permitted to perform, but it does enable an attacker to abuse legitimate user privileges.

Affected Systems

The affected product is the WordPress Comment Date and Gravatar remover plugin authored by Venugopal, with vulnerability present in all releases up to and including version 1.0. WordPress sites that have installed or activated this plugin and for which users have administrative or moderator access are susceptible.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk; the EPSS score of less than 1% suggests a low likelihood of exploitation at the time of publication, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to lure a logged‑in user to a crafted request that targets the plugin’s functionality, implying a network‑based attack vector. Because the flaw relies on a standard CSRF weakness, an attacker who can persuade a user to visit a malicious URL or embed a form would be able to perform the unwanted actions with the user’s privileges.

Generated by OpenCVE AI on May 1, 2026 at 14:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Uninstall or disable the Comment Date and Gravatar remover plugin from the WordPress installation.
  • Ensure that no legacy code from the plugin remains in the site’s themes or child‑themes; delete any related files manually if they were not removed automatically.
  • If the plugin cannot be removed, maintain strict session management and use the WordPress nonce system on any admin pages that may still interact with the plugin’s functionality to mitigate further CSRF attempts.

Generated by OpenCVE AI on May 1, 2026 at 14:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7832 Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover allows Cross Site Request Forgery. This issue affects Comment Date and Gravatar remover: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover allows Cross Site Request Forgery. This issue affects Comment Date and Gravatar remover: from n/a through 1.0. Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover remove-date-and-gravatar-under-comment allows Cross Site Request Forgery.This issue affects Comment Date and Gravatar remover: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00024}

epss

{'score': 0.00034}


Wed, 19 Mar 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Venugopal
Venugopal comment Date And Gravatar Remover
CPEs cpe:2.3:a:venugopal:comment_date_and_gravatar_remover:1.0:*:*:*:*:wordpress:*:*
Vendors & Products Venugopal
Venugopal comment Date And Gravatar Remover

Wed, 12 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover allows Cross Site Request Forgery. This issue affects Comment Date and Gravatar remover: from n/a through 1.0.
Title WordPress Comment Date and Gravatar remover plugin <= 1.0 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Venugopal Comment Date And Gravatar Remover
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:49.165Z

Reserved: 2025-03-11T08:08:42.175Z

Link: CVE-2025-28862

cve-icon Vulnrichment

Updated: 2025-03-12T15:03:26.803Z

cve-icon NVD

Status : Modified

Published: 2025-03-11T21:15:43.490

Modified: 2026-04-23T15:26:27.613

Link: CVE-2025-28862

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:15:20Z

Weaknesses