Description
Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Copy Media URL wp-copy-media-url allows Stored XSS.This issue affects WP Copy Media URL: from n/a through <= 2.1.
Published: 2025-03-31
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery flaw in the WP Copy Media URL plugin can be abused to inject persistent malicious scripts into the site’s database, allowing attackers to execute code in the browsers of any user who views the affected content. The vulnerability enables the storage of attacker‑controlled scripts which are later rendered in page contexts, leading to potential theft of user credentials, session hijacking, or defacement of the site. This weakness is identified as CWE‑352.

Affected Systems

Vulnerable systems include WordPress sites running Ashish Ajani’s WP Copy Media URL plugin version 2.1 or earlier. The plugin affects media URL handling functions and stores any injected payload until rendered by the site’s front‑end.

Risk and Exploitability

The flaw carries a CVSS score of 7.1, indicating high severity, but the EPSS score is less than 1%, suggesting a low likelihood of widespread exploitation at this time. It is not listed in the CISA KEV catalog. The vulnerability allows attackers to send CSRF requests that store malicious scripts within the plugin, which are later returned to site visitors. Specific prerequisites for exploitation, such as required user authentication or social engineering tactics, are not detailed in the advisory.

Generated by OpenCVE AI on May 1, 2026 at 12:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Copy Media URL to a version higher than 2.1
  • Disable or remove the plugin if the site no longer requires its functionality
  • Review and harden user role permissions to limit the ability of attackers to submit malicious requests

Generated by OpenCVE AI on May 1, 2026 at 12:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8792 Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Copy Media URL allows Stored XSS. This issue affects WP Copy Media URL: from n/a through 2.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Copy Media URL allows Stored XSS. This issue affects WP Copy Media URL: from n/a through 2.1. Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Copy Media URL wp-copy-media-url allows Stored XSS.This issue affects WP Copy Media URL: from n/a through <= 2.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Mon, 31 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 13:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Copy Media URL allows Stored XSS. This issue affects WP Copy Media URL: from n/a through 2.1.
Title WordPress WP Copy Media URL plugin <= 2.1 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:09.546Z

Reserved: 2025-03-31T10:05:51.139Z

Link: CVE-2025-31583

cve-icon Vulnrichment

Updated: 2025-03-31T16:22:00.939Z

cve-icon NVD

Status : Deferred

Published: 2025-03-31T13:15:51.407

Modified: 2026-04-23T15:28:00.640

Link: CVE-2025-31583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T12:15:17Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)