Description
Cross-Site Request Forgery (CSRF) vulnerability in Soft8Soft LLC Verge3D verge3d allows Cross Site Request Forgery.This issue affects Verge3D: from n/a through <= 4.8.2.
Published: 2025-03-27
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic cross-site request forgery flaw that allows an unauthenticated attacker to trick a logged-in user into performing unintended actions on the Verge3D plugin. An attacker can send a crafted request that exploits the lack of proper CSRF protection in the affected plugin versions, potentially altering settings or triggering e‑commerce transactions without the user's knowledge. The weakness is classified as CWE‑352 and represents a data integrity and privacy impact for end users whose actions could be subverted.

Affected Systems

The flaw affects Soft8Soft LLC’s Verge3D plugin for WordPress, all releases from the earliest known version through 4.8.2. Users of these versions should verify that the plugin is upgraded to a release later than 4.8.2, or that the affected functionality is disabled.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. CSRF attacks require the victim to be authenticated to the site and to have a browser session active; an attacker can craft a link or a form and lure the user to visit it. Because the plugin lacks adequate anti-CSRF tokens or proper request validation, the attack can be automated or executed through social engineering. Without an active session, exploitation is not possible, limiting the overall risk to authenticated users.

Generated by OpenCVE AI on May 1, 2026 at 12:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Verge3D to version 4.8.3 or newer to obtain the vendor patch that removes the CSRF weakness.
  • Disable or restrict any e‑commerce or publishing endpoints that are not needed in the site configuration to reduce the exposed surface area.
  • Configure WordPress to enforce CSRF tokens (wp_nonce) on all sensitive plugin actions and verify that these tokens are present before processing requests.

Generated by OpenCVE AI on May 1, 2026 at 12:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8360 Cross-Site Request Forgery (CSRF) vulnerability in Soft8Soft LLC Verge3D allows Cross Site Request Forgery. This issue affects Verge3D: from n/a through 4.8.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Soft8Soft LLC Verge3D allows Cross Site Request Forgery. This issue affects Verge3D: from n/a through 4.8.2. Cross-Site Request Forgery (CSRF) vulnerability in Soft8Soft LLC Verge3D verge3d allows Cross Site Request Forgery.This issue affects Verge3D: from n/a through <= 4.8.2.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Thu, 27 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Soft8Soft LLC Verge3D allows Cross Site Request Forgery. This issue affects Verge3D: from n/a through 4.8.2.
Title WordPress Verge3D Publishing and E-Commerce Plugin <= 4.8.2 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:58.573Z

Reserved: 2025-03-26T09:20:47.108Z

Link: CVE-2025-30833

cve-icon Vulnrichment

Updated: 2025-03-27T13:23:25.712Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:44.793

Modified: 2026-04-23T15:27:09.573

Link: CVE-2025-30833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T13:00:12Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)