Description
Cross-Site Request Forgery (CSRF) vulnerability in Jayesh Parejiya Social Media Links social-media-links allows Stored XSS.This issue affects Social Media Links: from n/a through <= 1.0.3.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery that allows an attacker to inject malicious scripts into the plugin’s stored content. A compromised user’s browser can submit an unauthenticated or authenticated request that saves attacker‑controlled JavaScript, which later runs for anyone viewing the affected social media links. This gives the attacker a persistent compromise of data integrity and potential credential theft, with full impact for any user who views the saved content.

Affected Systems

Jayesh Parejiya’s Social Media Links WordPress plugin, versions 1.0.3 and earlier. The plugin is widely used in WordPress installations.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog, so no large-scale exploitation campaigns are known. Attackers would need to craft a CSRF request—typically via a malicious link or embedded form—to submit to the plugin’s settings page. Because the plugin lacks proper CSRF checks, the request is processed and the arbitrary script is stored, leading to stored XSS when other site users view the links.

Generated by OpenCVE AI on April 30, 2026 at 22:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Social Media Links plugin to the latest version, ensuring that the patch removes the missing CSRF protection and sanitizes stored input.
  • If an immediate update is not feasible, temporarily de‑activate or uninstall the plugin to prevent the stored XSS vector from being exploited.
  • Apply a web application firewall or login‑protection plugin that enforces CSRF tokens on all admin requests, and configure all input fields in the WordPress admin area to filter out executable HTML and JavaScript.

Generated by OpenCVE AI on April 30, 2026 at 22:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11769 Cross-Site Request Forgery (CSRF) vulnerability in Jayesh Parejiya Social Media Links allows Stored XSS. This issue affects Social Media Links: from n/a through 1.0.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Jayesh Parejiya Social Media Links allows Stored XSS. This issue affects Social Media Links: from n/a through 1.0.3. Cross-Site Request Forgery (CSRF) vulnerability in Jayesh Parejiya Social Media Links social-media-links allows Stored XSS.This issue affects Social Media Links: from n/a through <= 1.0.3.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 15:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Jayesh Parejiya Social Media Links allows Stored XSS. This issue affects Social Media Links: from n/a through 1.0.3.
Title WordPress Social Media Links plugin <= 1.0.3 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:30.579Z

Reserved: 2025-04-16T06:22:58.198Z

Link: CVE-2025-39415

cve-icon Vulnrichment

Updated: 2025-04-17T18:09:39.313Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:51.167

Modified: 2026-04-23T15:29:30.657

Link: CVE-2025-39415

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T22:30:02Z

Weaknesses