Description
Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Image Autosave hacklog-remote-image-autosave allows Cross Site Request Forgery.This issue affects Hacklog Remote Image Autosave: from n/a through <= 2.1.0.
Published: 2025-03-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Hacklog Remote Image Autosave plugin contains a Cross‑Site Request Forgery flaw that allows an attacker to coerce an authenticated user into performing unintended actions, such as triggering the plugin’s image autosave function. The weakness is categorized as CWE‑352, indicating that the plugin fails to verify that state‑changing requests originate from legitimate user activity. In practice, this could lead to unauthorized content uploads, manipulation of the user’s media library, or other side effects depending on the plugin’s configuration. The CVSS score of 4.3 suggests a moderate base severity, with no presence in the CISA KEV catalog and an EPSS score of less than 1%, implying that the risk of active exploitation is currently low.

Affected Systems

The vulnerability affects the WordPress plugin named Hacklog Remote Image Autosave developed by HuangYe WuDeng, for all releases up to and including version 2.1.0. No specific sub‑versions are enumerated beyond "<= 2.1.0", and the vendor did not provide a list of affected minor releases.

Risk and Exploitability

Exploitation requires the victim to be logged into the site and to visit a crafted URL or submit a malicious form that triggers the autosave endpoint. Attackers can embed the request in a malicious page or email, banking on the fact that the plugin does not enforce a CSRF token or nonce. Given the low EPSS and absence from KEV, the likelihood of a real‑world exploitation is considered limited at present. However, the presence of the flaw makes the plugin a potential target for attackers targeting sites with the plugin enabled and users who may be receptive to social‑engineering methods.

Generated by OpenCVE AI on May 1, 2026 at 04:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Hacklog Remote Image Autosave to the latest release that eliminates the CSRF issue or to any version newer than 2.1.0.
  • If an upgrade is not possible, remove the plugin from the site or disable its autosave feature until a fix is available.
  • Ensure that all state‑changing requests in the WordPress site include a valid nonce or CSRF token—if the plugin adds such checks, verify they are correctly implemented and not bypassed by other site components.

Generated by OpenCVE AI on May 1, 2026 at 04:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7936 Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Image Autosave allows Cross Site Request Forgery. This issue affects Hacklog Remote Image Autosave: from n/a through 2.1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Image Autosave allows Cross Site Request Forgery. This issue affects Hacklog Remote Image Autosave: from n/a through 2.1.0. Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Image Autosave hacklog-remote-image-autosave allows Cross Site Request Forgery.This issue affects Hacklog Remote Image Autosave: from n/a through <= 2.1.0.
Title WordPress Hacklog Remote Image Autosave - <= <= 2.1.0 Cross Site Request Forgery (CSRF) Vulnerability WordPress Hacklog Remote Image Autosave plugin <= 2.1.0 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 25 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Image Autosave allows Cross Site Request Forgery. This issue affects Hacklog Remote Image Autosave: from n/a through 2.1.0.
Title WordPress Hacklog Remote Image Autosave - <= <= 2.1.0 Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:54.668Z

Reserved: 2025-03-24T13:00:15.939Z

Link: CVE-2025-30576

cve-icon Vulnrichment

Updated: 2025-03-25T17:49:17.513Z

cve-icon NVD

Status : Deferred

Published: 2025-03-24T14:15:29.790

Modified: 2026-06-17T09:08:57.107

Link: CVE-2025-30576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:30:08Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)