Description
Cross-Site Request Forgery (CSRF) vulnerability in riosisgroup Rio Video Gallery rio-video-gallery allows Stored XSS.This issue affects Rio Video Gallery: from n/a through <= 2.3.6.
Published: 2025-03-31
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery that allows an attacker to store malicious script code in the Rio Video Gallery plugin. Once stored, the payload will execute in the browsers of users who view the affected gallery content, providing the attacker with the ability to deface, steal session data, or perform other downstream attacks. The weakness is catalogued as CWE‑352, a classic CSRF flaw that enables unauthorized state‑changing requests.

Affected Systems

The plugin, available through riosisgroup under the name Rio Video Gallery for WordPress, is affected from its initial release through version 2.3.6. All installations of the plugin that have not been upgraded beyond 2.3.6 are at risk.

Risk and Exploitability

The assessed CVSS score of 7.1 reflects a high severity moderate‑to‑high impact with potential data exposure and defacement. The EPSS score of < 1 % indicates that, as of the current analysis, exploitation is unlikely yet still plausible, especially in environments where administrators may be exposed to CSRF vectors. The issue is not listed in CISA KEV, but the description indicates a CSRF vulnerability that could be exploited to persist malicious code. Based on the description, it is inferred that an attacker could trick a logged‑in user with editing rights in the gallery context into visiting a crafted request that submits unauthorized input, triggering the stored XSS. Thus an attacker only needs the victim to be authenticated and to have gallery editing privileges.

Generated by OpenCVE AI on May 2, 2026 at 02:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Rio Video Gallery plugin to the latest release beyond 2.3.6.
  • If an upgrade is not immediately feasible, restrict gallery editing functionality to administrative users only.
  • Deploy an additional CSRF protection mechanism, such as a site‑wide CSRF token middleware or a security plugin that validates state for all form submissions.

Generated by OpenCVE AI on May 2, 2026 at 02:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8822 Cross-Site Request Forgery (CSRF) vulnerability in riosisgroup Rio Video Gallery allows Stored XSS. This issue affects Rio Video Gallery: from n/a through 2.3.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in riosisgroup Rio Video Gallery allows Stored XSS. This issue affects Rio Video Gallery: from n/a through 2.3.6. Cross-Site Request Forgery (CSRF) vulnerability in riosisgroup Rio Video Gallery rio-video-gallery allows Stored XSS.This issue affects Rio Video Gallery: from n/a through <= 2.3.6.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Mon, 31 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 13:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in riosisgroup Rio Video Gallery allows Stored XSS. This issue affects Rio Video Gallery: from n/a through 2.3.6.
Title WordPress Rio Video Gallery plugin <= 2.3.6 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:09.165Z

Reserved: 2025-03-31T10:05:43.538Z

Link: CVE-2025-31566

cve-icon Vulnrichment

Updated: 2025-03-31T13:55:13.554Z

cve-icon NVD

Status : Deferred

Published: 2025-03-31T13:15:50.073

Modified: 2026-04-23T15:27:58.670

Link: CVE-2025-31566

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T03:00:13Z

Weaknesses