Description
Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Info Boxes Shortcode and Widget info-boxes-shortcode-and-widget allows Cross Site Request Forgery.This issue affects Info Boxes Shortcode and Widget: from n/a through <= 1.15.
Published: 2025-03-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a cross‑site request forgery flaw that lets an attacker trigger authenticated actions on a WordPress site without the user’s consent. If the user has administrative or content‑editing privileges, the attacker could create, modify or delete information boxes, effectively compromising the website’s integrity. The weakness is classified as CWE‑352 and carries a CVSS score of 4.3, indicating a moderate severity.

Affected Systems

The flaw exists in the OTWthemes Info Boxes Shortcode and Widget plugin, version 1.15 and earlier. Any WordPress installation that has this plugin installed and any user that is logged in when the malicious request is crafted is at risk.

Risk and Exploitability

The EPSS score is below 1%, so the probability of widespread exploitation is low, and it is not listed in the CISA KEV catalog. The attack requires an authenticated victim and the ability to send a crafted request to the site, making it a user‑dependent CSRF. Nonetheless, because it can affect site content and potentially do more damage than a simple denial of service, administrators should treat it as a moderate to high risk in environments where the plugin is widely used.

Generated by OpenCVE AI on May 1, 2026 at 04:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a version newer than 1.15 that includes the CSRF fix
  • If an immediate upgrade is not possible, disable the Info Boxes Shortcode and Widget plugin to eliminate the attack surface
  • Implement site‑wide CSRF protection, such as adding tokens to all forms or using a WordPress security plugin that enforces CSRF checks

Generated by OpenCVE AI on May 1, 2026 at 04:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7980 Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Info Boxes Shortcode and Widget allows Cross Site Request Forgery. This issue affects Info Boxes Shortcode and Widget: from n/a through 1.15.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Info Boxes Shortcode and Widget allows Cross Site Request Forgery. This issue affects Info Boxes Shortcode and Widget: from n/a through 1.15. Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Info Boxes Shortcode and Widget info-boxes-shortcode-and-widget allows Cross Site Request Forgery.This issue affects Info Boxes Shortcode and Widget: from n/a through <= 1.15.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Mon, 24 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Info Boxes Shortcode and Widget allows Cross Site Request Forgery. This issue affects Info Boxes Shortcode and Widget: from n/a through 1.15.
Title WordPress Info Boxes Shortcode And Widgets plugin <= 1.15 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:53.929Z

Reserved: 2025-03-24T12:59:49.932Z

Link: CVE-2025-30541

cve-icon Vulnrichment

Updated: 2025-03-24T14:50:29.859Z

cve-icon NVD

Status : Deferred

Published: 2025-03-24T14:15:23.180

Modified: 2026-04-23T15:26:49.700

Link: CVE-2025-30541

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:45:08Z

Weaknesses