Description
Cross-Site Request Forgery (CSRF) vulnerability in Labinator Labinator Content Types Duplicator labinator-content-types-duplicator allows Cross Site Request Forgery.This issue affects Labinator Content Types Duplicator: from n/a through <= 1.1.3.
Published: 2025-04-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a CSRF flaw in the Labinator Content Types Duplicator WordPress plugin. The flaw allows a malicious actor to cause the plugin to perform actions on behalf of a logged‑in user without their knowledge. The official description notes that the flaw exists from the initial release through version 1.1.3, but it does not detail the exact protection missing. The weakness is identified as CWE‑352, meaning improper validation of the origin of requests can lead to unintended actions by authenticated users, which can affect the integrity of site content or configuration.

Affected Systems

The issue affects WordPress sites running the Labinator Content Types Duplicator plugin version 1.1.3 or earlier. Administrators who have retained legacy releases from the initial release up to and including 1.1.3 are at risk; all newer releases are presumed fixed.

Risk and Exploitability

The CVSS score of 4.3 places the issue in the moderate severity range. The EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, supporting a low risk of widespread attacks. While the description does not specify the exact exploitation path, CSRF flaws typically require a user who is authenticated and has sufficient privileges to perform the compromised actions, and permission to trigger the offending request. If an attacker can craft a request that mimics a legitimate plugin action, the site may duplicate content, change settings, or otherwise alter its state without the user’s consent.

Generated by OpenCVE AI on May 2, 2026 at 08:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest version of the Labinator Content Types Duplicator plugin that addresses the CSRF flaw.
  • If an upgrade cannot be performed immediately, restrict administrative access to the plugin by removing the capability to manage it from all non‑administrator roles, ensuring that only trusted users can trigger its functions.
  • Deploy a web‑application firewall or similar filtering rule that blocks or challenges suspicious requests targeting the plugin’s action endpoints, mitigating the risk of forged requests while the plugin remains installed.

Generated by OpenCVE AI on May 2, 2026 at 08:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9230 Cross-Site Request Forgery (CSRF) vulnerability in Labinator Labinator Content Types Duplicator allows Cross Site Request Forgery. This issue affects Labinator Content Types Duplicator: from n/a through 1.1.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Labinator Labinator Content Types Duplicator allows Cross Site Request Forgery. This issue affects Labinator Content Types Duplicator: from n/a through 1.1.3. Cross-Site Request Forgery (CSRF) vulnerability in Labinator Labinator Content Types Duplicator labinator-content-types-duplicator allows Cross Site Request Forgery.This issue affects Labinator Content Types Duplicator: from n/a through <= 1.1.3.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 01 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Labinator Labinator Content Types Duplicator allows Cross Site Request Forgery. This issue affects Labinator Content Types Duplicator: from n/a through 1.1.3.
Title WordPress Labinator Content Types Duplicator Plugin <= 1.1.3 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:13.614Z

Reserved: 2025-04-01T13:20:24.606Z

Link: CVE-2025-31809

cve-icon Vulnrichment

Updated: 2025-04-01T18:29:07.320Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:20.437

Modified: 2026-04-23T15:28:20.283

Link: CVE-2025-31809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T08:45:38Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)