Description
Cross-Site Request Forgery (CSRF) vulnerability in MERGADO Mergado Pack mergado-marketing-pack allows Stored XSS.This issue affects Mergado Pack: from n/a through <= 4.2.1.
Published: 2025-04-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a Cross‑Site Request Forgery that allows a malicious actor to store a cross‑site scripting payload on the victim site. Once the payload is stored it can execute in the context of any user who visits the affected page, potentially leaking session cookies, hijacking accounts, or modifying page content. The weakness is identified as CWE‑352, representing a failure to verify that requests originate from legitimate users.

Affected Systems

The vulnerability affects the Mergado Pack plugin for WordPress, all releases up to and including version 4.2.1. Earlier versions are also impacted. This includes any WordPress site that has installed the plugin in those versions and has enabled write or configuration capabilities that the plugin modifies.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability represents a high‑risk condition. The EPSS score indicates that, at the moment of analysis, the likelihood of exploitation is very low—less than 1 percent—yet the attack surface remains present because a CSRF attack can be launched from a compromised user or by grabbing a session cookie. The vulnerability is not listed in the CISA KEV catalog, but that does not reduce the potential impact. Exposing stored XSS via a CSRF path allows attackers to inject persistent malicious code, which can be leveraged for credential theft, defacement, or further lateral movement on the site.

Generated by OpenCVE AI on May 1, 2026 at 00:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Mergado Pack plugin to a version later than 4.2.1, which contains the CSRF protection fix.
  • If an upgrade is not immediately possible, consider deactivating or uninstalling the Mergado Pack plugin to eliminate the attack vector until a patch can be applied.
  • Apply general anti‑CSRF measures such as token validation for all privileged write operations, enforce SameSite cookie attributes, and restrict administrative actions to users with appropriate roles.

Generated by OpenCVE AI on May 1, 2026 at 00:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10568 Cross-Site Request Forgery (CSRF) vulnerability in MERGADO Mergado Pack allows Stored XSS. This issue affects Mergado Pack: from n/a through 4.1.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in MERGADO Mergado Pack allows Stored XSS. This issue affects Mergado Pack: from n/a through 4.1.1. Cross-Site Request Forgery (CSRF) vulnerability in MERGADO Mergado Pack mergado-marketing-pack allows Stored XSS.This issue affects Mergado Pack: from n/a through <= 4.2.1.
Title WordPress Mergado Pack plugin <= 4.1.1 - CSRF to Stored XSS vulnerability WordPress Mergado Pack plugin <= 4.2.1 - Cross Site Request Forgery (CSRF) vulnerability
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 09 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 16:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in MERGADO Mergado Pack allows Stored XSS. This issue affects Mergado Pack: from n/a through 4.1.1.
Title WordPress Mergado Pack plugin <= 4.1.1 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:27.566Z

Reserved: 2025-04-09T11:21:18.307Z

Link: CVE-2025-32669

cve-icon Vulnrichment

Updated: 2025-04-09T17:42:40.509Z

cve-icon NVD

Status : Deferred

Published: 2025-04-09T17:15:51.023

Modified: 2026-04-23T15:29:19.043

Link: CVE-2025-32669

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T00:15:04Z

Weaknesses