Description
Cross-Site Request Forgery (CSRF) vulnerability in Sebastian Echeverry SCSS-Library scss-library allows Cross Site Request Forgery.This issue affects SCSS-Library: from n/a through <= 0.4.1.
Published: 2025-04-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cross‑Site Request Forgery in the SCSS‑Library WordPress plugin permits an attacker to trick a logged‑in user or the site itself into submitting malicious requests that perform privileged actions. Based on the description, it is inferred that the root cause may involve missing or improperly validated CSRF tokens on state‑changing endpoints, but the CVE description does not explicitly state this. An attacker can target the site by hosting a malicious page that submits a form or AJAX request to the plugin’s URLs, leading to unauthorized content modifications, configuration changes, or other unintended server‑side operations. The impact is local to the site that hosts the vulnerable plugin, potentially compromising both data integrity and confidentiality for users who are logged in or for the website operator.

Affected Systems

Software affected is the SCSS‑Library plugin for WordPress developed by Sebastian Echeverry. All releases from the initial release up to and including version 0.4.1 are vulnerable. WordPress sites running SCSS‑Library 0.4.1 or earlier lack the necessary CSRF protections on their plugin endpoints. No other plugins or WordPress components are mentioned as affected by this CVE.

Risk and Exploitability

The CVSS base score of 4.3 indicates a medium severity due to the limited impact. The EPSS score of less than 1% shows that public exploits are unlikely or currently rare. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed exploitation in the wild. The most likely attack vector is inferred to be web‑based, where the attacker hosts a crafted page that submits requests to the victim site through a user with an active session or through a vulnerable plugin endpoint. Because the flaw does not require authentication, any visitor to the site could be targeted, but the attacker must rely on the victim’s browser to execute the forged request.

Generated by OpenCVE AI on May 1, 2026 at 09:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SCSS‑Library plugin to the latest release that removes the CSRF flaw.
  • If an immediate upgrade is not feasible, restrict access to the plugin’s state‑changing URLs by IP whitelisting or by disabling related admin pages for unauthenticated users.
  • Apply an additional layer of CSRF protection, such as setting SameSite cookies or implementing a web‑application firewall rule that validates anti‑forge tokens for POST requests to the plugin’s endpoints.

Generated by OpenCVE AI on May 1, 2026 at 09:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-12087 Cross-Site Request Forgery (CSRF) vulnerability in Sebastian Echeverry SCSS-Library allows Cross Site Request Forgery. This issue affects SCSS-Library: from n/a through 0.4.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Sebastian Echeverry SCSS-Library allows Cross Site Request Forgery. This issue affects SCSS-Library: from n/a through 0.4.1. Cross-Site Request Forgery (CSRF) vulnerability in Sebastian Echeverry SCSS-Library scss-library allows Cross Site Request Forgery.This issue affects SCSS-Library: from n/a through <= 0.4.1.
Title WordPress SCSS-Library <= 0.4.1 - Cross Site Request Forgery (CSRF) Vulnerability WordPress SCSS-Library plugin <= 0.4.1 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 25 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Sebastian Echeverry SCSS-Library allows Cross Site Request Forgery. This issue affects SCSS-Library: from n/a through 0.4.1.
Title WordPress SCSS-Library <= 0.4.1 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:37.399Z

Reserved: 2025-04-24T14:22:09.615Z

Link: CVE-2025-46436

cve-icon Vulnrichment

Updated: 2025-04-24T19:55:47.045Z

cve-icon NVD

Status : Deferred

Published: 2025-04-24T16:15:34.770

Modified: 2026-04-23T15:29:59.140

Link: CVE-2025-46436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T09:15:13Z

Weaknesses