Description
Cross-Site Request Forgery (CSRF) vulnerability in oleglark VKontakte Cross-Post vkontakte-cross-post allows Stored XSS.This issue affects VKontakte Cross-Post: from n/a through <= 0.3.2.
Published: 2025-04-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from a Cross‑Site Request Forgery flaw that permits an attacker to submit a forged request to the VKontakte Cross‑Post plugin. The request contains malicious script that is then stored in the post content. When a normal site visitor views the post, the script executes in their browser, enabling the attacker to steal session cookies, deface content, or perform other client‑side attacks. This flaw classification aligns with CWE‑352 (CSRF).

Affected Systems

The affected product is the WordPress plugin VKontakte Cross‑Post, published by oleglark. All releases up to and including version 0.3.2 are vulnerable. Any WordPress installation that has this plugin installed, regardless of site traffic size, is at risk.

Risk and Exploitability

The CVSS score of 7.1 indicates medium‑to‑high severity, while the EPSS score of less than 1% suggests that the likelihood of this vulnerability being actively exploited is currently low, and it is not listed in the CISA KEV catalog. Exploitation requires the attacker to orchestrate a CSRF attack, most likely against an authenticated administrator or user who can trigger the plugin’s post‑creation endpoint. Once the malicious payload is stored, any user who views the compromised content will be affected, making the attack vector effectively network‑based yet dependent on user interaction with the site.

Generated by OpenCVE AI on April 30, 2026 at 23:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade VKontakte Cross‑Post to a version released after 0.3.2 that addresses the CSRF and stored XSS flaw.
  • If an immediate upgrade is not possible, disable the plugin or restrict its administrative access until a patched version is available.
  • Add CSRF token validation to the plugin’s form submissions and configure a web application firewall to block suspicious POST requests to the plugin’s endpoints, preventing unauthorized payload submissions.

Generated by OpenCVE AI on April 30, 2026 at 23:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10624 Cross-Site Request Forgery (CSRF) vulnerability in oleglark VKontakte Cross-Post allows Stored XSS. This issue affects VKontakte Cross-Post: from n/a through 0.3.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in oleglark VKontakte Cross-Post allows Stored XSS. This issue affects VKontakte Cross-Post: from n/a through 0.3.2. Cross-Site Request Forgery (CSRF) vulnerability in oleglark VKontakte Cross-Post vkontakte-cross-post allows Stored XSS.This issue affects VKontakte Cross-Post: from n/a through <= 0.3.2.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 09 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 16:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in oleglark VKontakte Cross-Post allows Stored XSS. This issue affects VKontakte Cross-Post: from n/a through 0.3.2.
Title WordPress VKontakte Cross-Post plugin <= 0.3.2 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:22.912Z

Reserved: 2025-04-09T11:19:20.928Z

Link: CVE-2025-32498

cve-icon Vulnrichment

Updated: 2025-04-09T17:40:57.424Z

cve-icon NVD

Status : Deferred

Published: 2025-04-09T17:15:43.263

Modified: 2026-04-23T15:28:59.500

Link: CVE-2025-32498

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T00:00:05Z

Weaknesses