Description
Cross-Site Request Forgery (CSRF) vulnerability in karrikas banner-manager banner-manager allows Stored XSS.This issue affects banner-manager: from n/a through <= 16.04.19.
Published: 2025-03-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The banner-manager plugin for WordPress can be tricked into storing malicious JavaScript because it fails to validate a CSRF token. An attacker can submit a forged request that inserts user‑agent‑containing scripts into the banner configuration. Whenever a site visitor loads the banner, the injected code runs in the visitor’s browser, allowing the attacker to steal cookies, session tokens or perform other malicious actions on the victim’s behalf. The weakness is classified as CWE‑352 – Cross‑Site Request Forgery leading to stored cross‑site scripting.

Affected Systems

The vulnerability affects the karrikas banner‑manager plugin for WordPress in all releases up to version 16.04.19 inclusive. Earlier or later releases are not known to be affected.

Risk and Exploitability

The CVSS score of 7.1 indicates a high level of severity, yet the EPSS score of less than 1% suggests that the probability of successful exploitation is currently very low. The flaw is not listed in the CISA KEV catalog, meaning no confirmed exploitable attacks have been reported. Exploitation requires an attacker to persuade the site owner or an authenticated administrator to trigger the CSRF request, or to place a malicious link or iframe that coerces a user into performing the request. Because the flaw resides in a widely used WordPress plugin, the potential impact is significant for any site that has the plugin active.

Generated by OpenCVE AI on May 1, 2026 at 04:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the banner-manager plugin to the latest version available (≥ 16.04.20).
  • If an update cannot be applied immediately, deactivate or uninstall the banner-manager plugin until a patch is released.
  • Review and apply updates for all other WordPress plugins and the core installation to reduce the overall attack surface.

Generated by OpenCVE AI on May 1, 2026 at 04:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7953 Cross-Site Request Forgery (CSRF) vulnerability in karrikas banner-manager allows Stored XSS. This issue affects banner-manager: from n/a through 16.04.19.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in karrikas banner-manager allows Stored XSS. This issue affects banner-manager: from n/a through 16.04.19. Cross-Site Request Forgery (CSRF) vulnerability in karrikas banner-manager banner-manager allows Stored XSS.This issue affects banner-manager: from n/a through <= 16.04.19.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 01 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in karrikas banner-manager allows Stored XSS. This issue affects banner-manager: from n/a through 16.04.19.
Title WordPress banner-manager plugin <= 16.04.19 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:54.286Z

Reserved: 2025-03-24T13:00:07.995Z

Link: CVE-2025-30565

cve-icon Vulnrichment

Updated: 2025-04-01T16:22:27.712Z

cve-icon NVD

Status : Deferred

Published: 2025-03-24T14:15:28.347

Modified: 2026-04-23T15:26:52.573

Link: CVE-2025-30565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:45:08Z

Weaknesses