Description
Cross-Site Request Forgery (CSRF) vulnerability in dangrossman WP Calais Auto Tagger calais-auto-tagger allows Cross Site Request Forgery.This issue affects WP Calais Auto Tagger: from n/a through <= 2.0.
Published: 2025-04-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a Cross‑Site Request Forgery flaw in the WordPress plugin WP Calais Auto Tagger that can be exploited to store malicious JavaScript in the site’s content. By forging a request from a logged‑in user, an attacker can inject user‑visible code that will run in the browsers of visitors. The impact is the ability to steal session cookies, deface pages, or perform further phishing attacks, as it results in stored cross‑site scripting.

Affected Systems

The issue affects the WordPress plugin WP Calais Auto Tagger from unknown early versions through version 2.0. It is distributed by dangrossman under the plugin name "WP Calais Auto Tagger" and is available on the WordPress plugin repository.

Risk and Exploitability

The CVSS base score of 7.1 indicates high severity. The EPSS score of less than 1 % suggests that, while the flaw is serious, it is currently predicted to be exploited infrequently. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector would be a web‑based CSRF attack that requires a victim to be authenticated on the site; an attacker can craft a link containing the malicious payload and entice the victim to click it. Once the forged request reaches the target, the plugin processes the data and stores the injected script, which is then rendered in subsequent page loads for all users.

Generated by OpenCVE AI on April 30, 2026 at 23:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest version of WP Calais Auto Tagger from the official plugin source or the developer’s website.
  • If an update is not available, deactivate or uninstall the WP Calais Auto Tagger plugin to remove the vulnerable code path.
  • Inspect the site’s content and custom fields for any injected JavaScript that may have been stored by the plugin, and delete or neutralize those entries.

Generated by OpenCVE AI on April 30, 2026 at 23:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10593 Cross-Site Request Forgery (CSRF) vulnerability in dangrossman WP Calais Auto Tagger allows Cross Site Request Forgery. This issue affects WP Calais Auto Tagger: from n/a through 2.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in dangrossman WP Calais Auto Tagger allows Cross Site Request Forgery. This issue affects WP Calais Auto Tagger: from n/a through 2.0. Cross-Site Request Forgery (CSRF) vulnerability in dangrossman WP Calais Auto Tagger calais-auto-tagger allows Cross Site Request Forgery.This issue affects WP Calais Auto Tagger: from n/a through <= 2.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 09 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 16:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in dangrossman WP Calais Auto Tagger allows Cross Site Request Forgery. This issue affects WP Calais Auto Tagger: from n/a through 2.0.
Title WordPress WP Calais Auto Tagger plugin <= 2.0 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:04:57.977Z

Reserved: 2025-04-09T11:20:02.682Z

Link: CVE-2025-32563

cve-icon Vulnrichment

Updated: 2025-04-09T17:41:33.077Z

cve-icon NVD

Status : Deferred

Published: 2025-04-09T17:15:46.030

Modified: 2026-04-23T15:29:06.900

Link: CVE-2025-32563

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T00:00:05Z

Weaknesses