Description
Cross-Site Request Forgery (CSRF) vulnerability in Clearbit Clearbit Reveal clearbit allows Cross Site Request Forgery.This issue affects Clearbit Reveal: from n/a through <= 1.0.6.
Published: 2025-04-01
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery flaw exists in Clearbit Reveal for WordPress that allows a malicious actor to submit arbitrary requests on behalf of a logged‑in administrator or other authenticated user. By inducing the victim to click a crafted link or visit a malicious page, the attacker can trigger privileged actions without the user’s explicit consent. The vulnerability stems from missing or improperly validated CSRF tokens, which is identified as CWE‑352. The impact is the unauthorized execution of actions that the authenticated user is authorized to perform, potentially leading to data modification, configuration changes, or disclosure of sensitive content. The severity, as gauged by the CVSS score of 5.4, indicates a moderate risk but not a critical threat.

Affected Systems

WordPress sites running Clearbit Reveal version 1.0.6 or earlier are affected. Any installation of the Clearbit Reveal plugin through version 1.0.6 or below carries the risk, as the flaw is present across all these releases.

Risk and Exploitability

The CVSS score of 5.4 points to moderate impact, while the EPSS score of less than 1% suggests a low probability of exploitation in current threat landscapes. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is a web‑based exploitation where a compromised or malicious site can lure an authenticated WordPress user into unknowingly submitting a forged request. Successful exploitation requires the victim to be authenticated to the site and to have sufficient privileges to perform the affected action. Because the flaw does not provide remote code execution or privilege escalation beyond the victim’s own user rights, the overall risk remains within the moderate range.

Generated by OpenCVE AI on May 1, 2026 at 02:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Clearbit Reveal to a version higher than 1.0.6 when it becomes available
  • If an upgrade is not immediately possible, disable or delete the Clearbit Reveal plugin from the WordPress installation
  • Apply generic Cross‑Site Request Forgery protection, such as ensuring all state‑changing endpoints validate anti‑CSRF tokens or use same‑origin policies

Generated by OpenCVE AI on May 1, 2026 at 02:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9235 Cross-Site Request Forgery (CSRF) vulnerability in Clearbit Clearbit Reveal allows Cross Site Request Forgery. This issue affects Clearbit Reveal: from n/a through 1.0.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Clearbit Clearbit Reveal allows Cross Site Request Forgery. This issue affects Clearbit Reveal: from n/a through 1.0.6. Cross-Site Request Forgery (CSRF) vulnerability in Clearbit Clearbit Reveal clearbit allows Cross Site Request Forgery.This issue affects Clearbit Reveal: from n/a through <= 1.0.6.
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Tue, 01 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Clearbit Clearbit Reveal allows Cross Site Request Forgery. This issue affects Clearbit Reveal: from n/a through 1.0.6.
Title WordPress Clearbit Reveal plugin <= 1.0.6 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:12.722Z

Reserved: 2025-04-01T13:19:54.844Z

Link: CVE-2025-31785

cve-icon Vulnrichment

Updated: 2025-04-01T19:11:50.416Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:16.410

Modified: 2026-04-23T15:28:17.353

Link: CVE-2025-31785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T02:15:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)