Description
Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Right Click Disable OR Ban right-click-disable-or-ban allows Stored XSS.This issue affects Right Click Disable OR Ban: from n/a through <= 1.1.17.
Published: 2025-04-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery that allows an attacker to inject a stored malicious script into the WordPress database via the Right Click Disable OR Ban plugin. Once the admin authorizes a forged request, the payload becomes part of the site’s content and is executed in the browsers of all visitors. This can lead to defacement, phishing, or credential theft for users, compromising confidentiality and application integrity. The weakness is classified as CWE‑352.

Affected Systems

A WP Life right‑click‑disable‑or‑ban plugin, versions up to and including 1.1.17, is affected. Any WordPress installation that has this plugin installed and active on a server running a vulnerable version is at risk.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability is moderately severe. The EPSS score of less than 1 % indicates a low probability of exploitation at present, yet the lack of a defensive token makes the attack vector trivial for an attacker who can coerce an authenticated admin into visiting a crafted URL. The vulnerability is not listed in the CISA KEV catalog, but should still be addressed promptly because the impact to site users can be significant. The attack requires an authenticated administrator but any user with that privilege can be lured to trigger the forged request, making the exploitation path straightforward once privileged access is available.

Generated by OpenCVE AI on April 30, 2026 at 22:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Right Click Disable OR Ban plugin to version 1.1.18 or later.
  • If an upgrade is not immediately possible, remove the plugin from the WordPress installation or disable it in the admin dashboard.
  • Ensure the WordPress core, theme, and other plugins are kept up to date to reduce the overall attack surface.
  • After remediation, review site content for injected scripts and remove any malicious code.
  • Consider deploying a Web Application Firewall or content‑security‑policy header to block execution of unexpected scripts as a supplementary safeguard.

Generated by OpenCVE AI on April 30, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11325 Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Right Click Disable OR Ban allows Stored XSS. This issue affects Right Click Disable OR Ban: from n/a through 1.1.17.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Right Click Disable OR Ban allows Stored XSS. This issue affects Right Click Disable OR Ban: from n/a through 1.1.17. Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Right Click Disable OR Ban right-click-disable-or-ban allows Stored XSS.This issue affects Right Click Disable OR Ban: from n/a through <= 1.1.17.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 16 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Apr 2025 13:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Right Click Disable OR Ban allows Stored XSS. This issue affects Right Click Disable OR Ban: from n/a through 1.1.17.
Title WordPress Right Click Disable OR Ban plugin <= 1.1.17 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:34.534Z

Reserved: 2025-04-16T06:24:54.679Z

Link: CVE-2025-39548

cve-icon Vulnrichment

Updated: 2025-04-16T13:19:10.636Z

cve-icon NVD

Status : Deferred

Published: 2025-04-16T13:15:47.713

Modified: 2026-04-23T15:29:46.150

Link: CVE-2025-39548

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T22:45:03Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)