Description
Cross-Site Request Forgery (CSRF) vulnerability in wpzinc Post to Social Media – WordPress to Hootsuite wp-to-hootsuite allows Cross Site Request Forgery.This issue affects Post to Social Media – WordPress to Hootsuite: from n/a through <= 1.5.8.
Published: 2025-04-04
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in the WordPress to Hootsuite plugin allows a Cross‑Site Request Forgery (CSRF) attack. An attacker can trick an authenticated user into navigating to a crafted URL that triggers the plugin to perform actions on the user’s behalf without their consent. Because the flaw resides in the plugin’s form handling logic, any action that the plugin protects can be hijacked, potentially leading to unauthorized posts or configuration changes on the linked Hootsuite account.

Affected Systems

The affected product is the WordPress to Hootsuite plugin, developed by wpzinc under the name Post to Social Media – WordPress to Hootsuite. All releases from the initial version through version 1.5.8 are susceptible. Any WordPress site running these plugin versions with an active authenticated user is impacted.

Risk and Exploitability

The CVSS score of 4.3 places this issue in the medium severity range, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at the current time. The vulnerability is not listed in CISA’s KEV catalog. The attack would likely require an attacker to lure an authenticated site user to a malicious page; the user’s session cookie would then be used to send a request that the plugin processes, causing the unintended action. Although exploitation probability is low, the impact could be significant if the unauthorized action manipulates a user’s social media presence.

Generated by OpenCVE AI on May 1, 2026 at 11:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the wp‑to‑hootsuite plugin to the latest available version.
  • Verify that the updated plugin includes CSRF protection by inspecting its form processing code or developer notes.
  • If an update is not immediately available, disable the plugin or remove it until a patched version is released to prevent exploitation.

Generated by OpenCVE AI on May 1, 2026 at 11:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9778 Cross-Site Request Forgery (CSRF) vulnerability in wpzinc Post to Social Media – WordPress to Hootsuite allows Cross Site Request Forgery. This issue affects Post to Social Media – WordPress to Hootsuite: from n/a through 1.5.8.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in wpzinc Post to Social Media – WordPress to Hootsuite allows Cross Site Request Forgery. This issue affects Post to Social Media – WordPress to Hootsuite: from n/a through 1.5.8. Cross-Site Request Forgery (CSRF) vulnerability in wpzinc Post to Social Media – WordPress to Hootsuite wp-to-hootsuite allows Cross Site Request Forgery.This issue affects Post to Social Media – WordPress to Hootsuite: from n/a through <= 1.5.8.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 04 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in wpzinc Post to Social Media – WordPress to Hootsuite allows Cross Site Request Forgery. This issue affects Post to Social Media – WordPress to Hootsuite: from n/a through 1.5.8.
Title WordPress WP to Hootsuite plugin <= 1.5.8 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:20.069Z

Reserved: 2025-04-04T10:02:22.506Z

Link: CVE-2025-32267

cve-icon Vulnrichment

Updated: 2025-04-04T19:59:30.869Z

cve-icon NVD

Status : Deferred

Published: 2025-04-04T16:15:37.713

Modified: 2026-04-23T15:28:52.217

Link: CVE-2025-32267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T11:15:15Z

Weaknesses