Description
Cross-Site Request Forgery (CSRF) vulnerability in usermaven Usermaven usermaven allows Cross Site Request Forgery.This issue affects Usermaven: from n/a through <= 1.2.1.
Published: 2025-03-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Usermaven plugin for WordPress contains a CSRF flaw that allows an attacker to trick a logged-in user into performing unintended state‑changing actions. This weakness is classified as CWE-352 and can lead to unauthorized modifications of user data or configuration if the site never validates the source of requests. While the flaw does not provide direct code execution, its impact is the loss of integrity of user‑managed data and potential escalation of privileges within the WordPress installation.

Affected Systems

The vulnerable component is the Usermaven WordPress plugin, versions 1.2.1 and earlier. Any WordPress site that has installed this plugin without upgrading beyond version 1.2.1 is at risk. The vulnerability affects all releases from the starting point of the plugin’s public availability up to and including 1.2.1.

Risk and Exploitability

With a CVSS score of 4.3 the issue is of moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers would typically need a victim who is already authenticated to the site and could be induced to visit a malicious page that submits a forged request against the Usermaven endpoints. The exploit is straightforward for a skilled adversary, but requires user interaction.

Generated by OpenCVE AI on May 1, 2026 at 12:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Usermaven plugin release that removes the CSRF flaw (any version newer than 1.2.1).
  • If an immediate upgrade is not possible, add a custom CSRF token check or verify a trusted‑origin header so that only requests originating from your own domain are processed by the plugin.
  • Enhance overall WordPress security by deploying a recognized CSRF protection plugin or enabling WordPress’s built‑in nonce system for all forms that alter user data.

Generated by OpenCVE AI on May 1, 2026 at 12:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8567 Cross-Site Request Forgery (CSRF) vulnerability in usermaven Usermaven allows Cross Site Request Forgery. This issue affects Usermaven: from n/a through 1.2.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in usermaven Usermaven allows Cross Site Request Forgery. This issue affects Usermaven: from n/a through 1.2.1. Cross-Site Request Forgery (CSRF) vulnerability in usermaven Usermaven usermaven allows Cross Site Request Forgery.This issue affects Usermaven: from n/a through <= 1.2.1.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 28 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 09:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in usermaven Usermaven allows Cross Site Request Forgery. This issue affects Usermaven: from n/a through 1.2.1.
Title WordPress Usermaven plugin <= 1.2.1 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:04.950Z

Reserved: 2025-03-26T09:25:58.783Z

Link: CVE-2025-31079

cve-icon Vulnrichment

Updated: 2025-03-28T13:48:41.450Z

cve-icon NVD

Status : Deferred

Published: 2025-03-28T10:15:16.963

Modified: 2026-04-23T15:27:39.973

Link: CVE-2025-31079

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T12:45:15Z

Weaknesses