Description
Cross-Site Request Forgery (CSRF) vulnerability in Ashok G Easy Child Theme Creator easy-child-theme-creator allows Cross Site Request Forgery.This issue affects Easy Child Theme Creator: from n/a through <= 1.3.1.
Published: 2025-05-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from missing CSRF token validation (CWE-352) during certain actions performed by the Easy Child Theme Creator plugin. As a result, an attacker can trick an authenticated WordPress administrator into executing unwanted changes to the site’s theme settings or other administrative actions, compromising the integrity of the site’s appearance and functionality. While this does not provide direct code execution, the impact can be significant by altering site presentation or enabling further attacks if other privileged actions are available.

Affected Systems

The affected product is the WordPress Easy Child Theme Creator plugin by Ashok G, versions from the initial release through 1.3.1. Any WordPress site running one of these versions remains vulnerable until the component is updated to a fixed release.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk, and an EPSS score of less than 1% suggests a very low likelihood of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to lure an authenticated user to a malicious URL or crafted link; once the authenticated request is sent, the plugin processes the action without further verification, enabling the attacker to perform unauthorized changes.

Generated by OpenCVE AI on April 30, 2026 at 19:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Easy Child Theme Creator to the latest version that includes CSRF token validation.
  • If an upgrade is not immediately possible, disable the plugin or its state‑changing features for non‑admin roles to prevent exploitation.
  • Implement or enforce site‑wide CSRF protection for WordPress, such as referer checks or a CSRF token middleware.

Generated by OpenCVE AI on April 30, 2026 at 19:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-15747 Cross-Site Request Forgery (CSRF) vulnerability in Ashok G Easy Child Theme Creator allows Cross Site Request Forgery.This issue affects Easy Child Theme Creator: from n/a through 1.3.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Ashok G Easy Child Theme Creator allows Cross Site Request Forgery.This issue affects Easy Child Theme Creator: from n/a through 1.3.1. Cross-Site Request Forgery (CSRF) vulnerability in Ashok G Easy Child Theme Creator easy-child-theme-creator allows Cross Site Request Forgery.This issue affects Easy Child Theme Creator: from n/a through <= 1.3.1.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Mon, 19 May 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 May 2025 17:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Ashok G Easy Child Theme Creator allows Cross Site Request Forgery.This issue affects Easy Child Theme Creator: from n/a through 1.3.1.
Title WordPress Easy Child Theme Creator plugin <= 1.3.1 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:17:59.678Z

Reserved: 2025-04-16T06:22:29.272Z

Link: CVE-2025-39375

cve-icon Vulnrichment

Updated: 2025-05-19T21:15:18.251Z

cve-icon NVD

Status : Deferred

Published: 2025-05-19T17:15:26.580

Modified: 2026-04-23T15:29:26.213

Link: CVE-2025-39375

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T19:45:26Z

Weaknesses