Description
Cross-Site Request Forgery (CSRF) vulnerability in Ahsanullah Akanda Wp Custom CMS Block wp-custom-cms-block allows Stored XSS.This issue affects Wp Custom CMS Block: from n/a through <= 2.1.
Published: 2025-04-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw that lets an attacker submit a crafted request to the WordPress Wp Custom CMS Block plugin. Because the plugin does not validate the request origin, the attacker can inject malicious JavaScript which is then stored in the plugin’s content fields. When visitors load the affected page, the stored script executes with the authority of the visitor, enabling session hijacking, content defacement or other malicious actions. The weakness is identified as CWE‑352.

Affected Systems

Affected systems include installations of the Wp Custom CMS Block plugin from versions up to and including 2.1. This plugin is developed by Ahsanullah Akanda and is listed in the WordPress plugin repository. Sites running any of these versions are vulnerable; newer releases after 2.1 are not impacted according to the available data.

Risk and Exploitability

The CVSS score of 7.1 describes a medium‑to‑high severity event, and the EPSS score of less than 1% indicates exploitation is still very unlikely but not impossible. The vulnerability is not currently listed in the CISA KEV catalog, so no active exploitation campaigns have been reported yet. However, because the flaw relies on a single forged request, an attacker who can coerce a user to visit the site or perform a credential‑stealing attack could inject persistent code. The absence of a formal workaround means mitigation must rely on applying a patch or disabling the plugin.

Generated by OpenCVE AI on April 30, 2026 at 20:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Wp Custom CMS Block to a version newer than 2.1, or uninstall the plugin if it is no longer needed.
  • Deploy a security plugin that enforces CSRF tokens for all form submissions.
  • Implement HTTP security headers such as Content‑Security‑Policy to limit the effect of any residual XSS scripts.

Generated by OpenCVE AI on April 30, 2026 at 20:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-12053 Cross-Site Request Forgery (CSRF) vulnerability in digontoahsan Wp Custom CMS Block allows Stored XSS. This issue affects Wp Custom CMS Block: from n/a through 2.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in digontoahsan Wp Custom CMS Block allows Stored XSS. This issue affects Wp Custom CMS Block: from n/a through 2.1. Cross-Site Request Forgery (CSRF) vulnerability in Ahsanullah Akanda Wp Custom CMS Block wp-custom-cms-block allows Stored XSS.This issue affects Wp Custom CMS Block: from n/a through <= 2.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 25 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in digontoahsan Wp Custom CMS Block allows Stored XSS. This issue affects Wp Custom CMS Block: from n/a through 2.1.
Title WordPress Wp Custom CMS Block plugin <= 2.1 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:37.864Z

Reserved: 2025-04-24T14:22:30.738Z

Link: CVE-2025-46457

cve-icon Vulnrichment

Updated: 2025-04-24T19:53:32.143Z

cve-icon NVD

Status : Deferred

Published: 2025-04-24T16:15:36.623

Modified: 2026-04-23T15:30:01.580

Link: CVE-2025-46457

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T21:00:15Z

Weaknesses