Description
Cross-Site Request Forgery (CSRF) vulnerability in Nks publish post email notification publish-post-email-notification allows Cross Site Request Forgery.This issue affects publish post email notification: from n/a through <= 1.0.2.3.
Published: 2025-03-27
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to change the configuration of the Nks publish post email notification plugin. By forging a request to the plugin’s settings endpoint, an adversary can alter email recipients, modify notification rules, or disable the plugin’s email functionality. The weakness is classified as CWE‑352. Because the attacker can manipulate the plugin’s behavior, the potential impact includes unauthorized disclosure of email content, injection of malicious links, or spreading of spam through the website’s users.

Affected Systems

The flaw affects WordPress sites running the Nks publish post email notification plugin version 1.0.2.3 or earlier. No other vendor or product versions are listed.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of less than 1 % implies a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, reducing the probability that it is being actively abused. The attack vector is inferred to be web‑based, requiring the sender to craft a forged HTTP request to change settings, which typically requires the victim to be logged in as an administrator. Given the moderate score and low exploitation probability, the overall risk to a site depends on whether the plugin is in use and whether the site’s users routinely access administrative functions.

Generated by OpenCVE AI on May 1, 2026 at 04:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Nks publish post email notification plugin to the latest available release that includes the CSRF fix.
  • If a patch is not yet available, disable the plugin or restrict access to its settings page to a narrow set of trusted administrators.
  • Add a CSRF token or nonce to the settings form manually, or use a security plugin that enforces CSRF protection until the vendor releases a fixed version.

Generated by OpenCVE AI on May 1, 2026 at 04:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8363 Cross-Site Request Forgery (CSRF) vulnerability in Nks publish post email notification allows Cross Site Request Forgery. This issue affects publish post email notification: from n/a through 1.0.2.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Nks publish post email notification allows Cross Site Request Forgery. This issue affects publish post email notification: from n/a through 1.0.2.3. Cross-Site Request Forgery (CSRF) vulnerability in Nks publish post email notification publish-post-email-notification allows Cross Site Request Forgery.This issue affects publish post email notification: from n/a through <= 1.0.2.3.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Thu, 27 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Nks publish post email notification allows Cross Site Request Forgery. This issue affects publish post email notification: from n/a through 1.0.2.3.
Title WordPress publish post email notification plugin <= 1.0.2.3 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:57.965Z

Reserved: 2025-03-26T09:20:32.696Z

Link: CVE-2025-30816

cve-icon Vulnrichment

Updated: 2025-03-27T13:27:53.338Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:42.773

Modified: 2026-04-23T15:27:07.560

Link: CVE-2025-30816

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:15:08Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)