Description
Cross-Site Request Forgery (CSRF) vulnerability in Wladyslaw Madejczyk AF Tell a Friend af-tell-a-friend allows Stored XSS.This issue affects AF Tell a Friend: from n/a through <= 1.4.
Published: 2025-04-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A cross‑site request forgery flaw in the AF Tell a Friend WordPress plugin permits an attacker to forge a request that causes the plugin to store an arbitrary script payload. Once the payload is stored, any subsequent user who views the affected page will have the script executed in their browser, allowing the attacker to hijack sessions, steal cookies, deface content, or propagate malware. The vulnerability is rooted in CWE‑352, a classic CSRF weakness that leads to stored XSS when combined with template or content injection bugs. The impact is primarily a compromise of confidentiality and data integrity for users who view the affected content, and the extent can reach site‑wide if the payload is placed in a globally rendered component.

Affected Systems

The AF Tell a Friend plugin, developed by Wladyslaw Madejczyk, is affected in all releases through version 1.4. The plugin is a WordPress add‑on that allows users to share content via a “tell a friend” form. No specific WordPress core version constraint is listed, so any WordPress installation with the plugin v1.4 or older is vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity, while the EPSS of less than 1 % suggests a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog, implying no known mass exploitation events have been reported. An attacker can exploit the flaw by sending a crafted link or form to a logged‑in administrator or other privileged user, taking advantage of the missing CSRF token. Successful exploitation requires the victim to follow the link and the plugin to accept the request and persist the malicious script. If the attacker controls a user’s browser session or leverages social engineering, the stored XSS can be activated across the site. The absence of a KEV listing reduces urgency, but the CVSS rating warrants timely remediation.

Generated by OpenCVE AI on April 30, 2026 at 23:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AF Tell a Friend plugin to the latest version available, which removes the CSRF flaw and the associated XSS injection point.
  • If an upgrade is not immediately feasible, uninstall or deactivate the vulnerable plugin until a safe version is released.
  • Apply a site‑wide CSRF mitigation such as requiring a nonce or origin check on all form submissions, ensuring that the tell‑a‑friend functionality cannot be triggered without a legitimate user request.

Generated by OpenCVE AI on April 30, 2026 at 23:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10632 Cross-Site Request Forgery (CSRF) vulnerability in Wladyslaw Madejczyk AF Tell a Friend allows Stored XSS. This issue affects AF Tell a Friend: from n/a through 1.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Wladyslaw Madejczyk AF Tell a Friend allows Stored XSS. This issue affects AF Tell a Friend: from n/a through 1.4. Cross-Site Request Forgery (CSRF) vulnerability in Wladyslaw Madejczyk AF Tell a Friend af-tell-a-friend allows Stored XSS.This issue affects AF Tell a Friend: from n/a through <= 1.4.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 09 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 16:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Wladyslaw Madejczyk AF Tell a Friend allows Stored XSS. This issue affects AF Tell a Friend: from n/a through 1.4.
Title WordPress AF Tell a Friend plugin <= 1.4 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:06.195Z

Reserved: 2025-03-28T10:59:36.421Z

Link: CVE-2025-31404

cve-icon Vulnrichment

Updated: 2025-04-09T17:40:28.247Z

cve-icon NVD

Status : Deferred

Published: 2025-04-09T17:15:39.423

Modified: 2026-04-23T15:27:45.963

Link: CVE-2025-31404

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T23:45:03Z

Weaknesses