Description
Cross-Site Request Forgery (CSRF) vulnerability in John Weissberg Print Science Designer print-science-designer allows Stored XSS.This issue affects Print Science Designer: from n/a through <= 1.3.155.
Published: 2025-04-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a CSRF flaw that permits an attacker to inject malicious script that is permanently stored by the Print Science Designer plugin. A compromised script executed in the context of a site visitor can expose sensitive information, deface the site, or hijack user sessions. The stored type of XSS means the attack payload remains on the site after the initial request and will affect all users who view the impacted content. The weakness is identified as CWE‑352, emphasizing the importance of correct CSRF protection and input validation.

Affected Systems

Affected is the WordPress plugin Print Science Designer by John Weissberg. Any installation version up to 1.3.155 inclusive is vulnerable; newer releases are not listed as impacted. Site owners using this plugin should verify their installed version and update if necessary.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, indicating moderately high severity, while the EPSS score of less than 1 % suggests exploitation is currently unlikely but not impossible. It is not listed in CISA’s KEV catalog, but the nature of the flaw permits arbitrary code execution in the context of authenticated users, so it is still a significant concern. Attackers would need to lure a legitimate user into visiting a crafted link or embed malicious content in a context that triggers the CSRF flaw; the attack vector is web‑based, relying on the normal administrative interface of the plugin.

Generated by OpenCVE AI on April 30, 2026 at 21:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Print Science Designer to version 1.3.156 or later, which removes the CSRF and stored XSS flaw.
  • If an upgrade is not immediately feasible, permanently deactivate or delete the Print Science Designer plugin to eliminate the attack surface.
  • Add a site‑wide CSRF token verification mechanism to all forms and validate the Origin/Referer headers, ensuring that only legitimate requests are processed.

Generated by OpenCVE AI on April 30, 2026 at 21:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-12044 Cross-Site Request Forgery (CSRF) vulnerability in John Weissberg Print Science Designer allows Stored XSS. This issue affects Print Science Designer: from n/a through 1.3.155.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in John Weissberg Print Science Designer allows Stored XSS. This issue affects Print Science Designer: from n/a through 1.3.155. Cross-Site Request Forgery (CSRF) vulnerability in John Weissberg Print Science Designer print-science-designer allows Stored XSS.This issue affects Print Science Designer: from n/a through <= 1.3.155.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 25 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in John Weissberg Print Science Designer allows Stored XSS. This issue affects Print Science Designer: from n/a through 1.3.155.
Title WordPress Print Science Designer plugin <= 1.3.155 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:38.601Z

Reserved: 2025-04-24T14:22:38.654Z

Link: CVE-2025-46465

cve-icon Vulnrichment

Updated: 2025-04-24T19:55:25.850Z

cve-icon NVD

Status : Deferred

Published: 2025-04-24T16:15:37.173

Modified: 2026-04-23T15:30:02.783

Link: CVE-2025-46465

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T21:15:06Z

Weaknesses