Description
Cross-Site Request Forgery (CSRF) vulnerability in Javier Revilla ValidateCertify validar-certificados-de-cursos allows Cross Site Request Forgery.This issue affects ValidateCertify: from n/a through <= 1.6.1.
Published: 2025-03-27
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ValidateCertify plugin for WordPress contains a CSRF flaw that enables an attacker to make the authenticated user perform privileged actions without the user’s consent. Because the vulnerability does not require authentication, the attacker only needs the victim to be logged into a WordPress site where the plugin is installed. If exploited, an attacker could trigger actions such as approving or rejecting certificates, or otherwise manipulating data stored by the plugin, potentially undermining the integrity of course certification workflows.

Affected Systems

Any WordPress installation that has the ValidateCertify plugin version 1.6.1 or earlier. The affected product is named ValidateCertify and is published by Javier Revilla. No further version constraints are listed beyond the "<= 1.6.1" range; earlier undocumented releases are also vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk level, primarily due to the lack of required authentication but also limited impact scope. The EPSS score of less than 1% suggests the likelihood of active exploitation is currently low, and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is a malicious web page or email that loads a URL crafted to push the victim’s browser to send a state‑changing request to the plugin’s endpoints while the user is authenticated to the target WordPress site. In the absence of additional defensive controls, the absence of a CSRF token or nonce is the key weakness enabling the attack.

Generated by OpenCVE AI on May 1, 2026 at 13:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the ValidateCertify plugin to a version newer than 1.6.1 once it becomes available to eliminate the CSRF flaw.
  • If an upgrade is not yet possible, disable or otherwise lock down any state‑changing features of the plugin until the patch is applied.
  • Ensure that all form submissions in the WordPress site include a unique, verifiable nonce or token so that any state‑changing request without a valid token is rejected.

Generated by OpenCVE AI on May 1, 2026 at 13:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8389 Cross-Site Request Forgery (CSRF) vulnerability in Javier Revilla ValidateCertify allows Cross Site Request Forgery. This issue affects ValidateCertify: from n/a through 1.6.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Javier Revilla ValidateCertify allows Cross Site Request Forgery. This issue affects ValidateCertify: from n/a through 1.6.1. Cross-Site Request Forgery (CSRF) vulnerability in Javier Revilla ValidateCertify validar-certificados-de-cursos allows Cross Site Request Forgery.This issue affects ValidateCertify: from n/a through <= 1.6.1.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Thu, 27 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Javier Revilla ValidateCertify allows Cross Site Request Forgery. This issue affects ValidateCertify: from n/a through 1.6.1.
Title WordPress ValidateCertify plugin <= 1.6.1 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:57.915Z

Reserved: 2025-03-26T09:20:25.505Z

Link: CVE-2025-30811

cve-icon Vulnrichment

Updated: 2025-03-27T13:58:47.190Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:42.103

Modified: 2026-04-23T15:27:06.990

Link: CVE-2025-30811

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T13:15:20Z

Weaknesses