Description
Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Attachment hacklog-remote-attachment allows Stored XSS.This issue affects Hacklog Remote Attachment: from n/a through <= 1.3.2.
Published: 2025-04-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Hacklog Remote Attachment permits an attacker to send forged requests that cause the plugin to store malicious JavaScript in its database. When a user later views a page containing the stored payload, the script runs in the victim's browser, enabling session hijacking, credential theft or defacement. The weakness is a classic CSRF debuff (CWE‑352). Because the payload is stored, the impact persists across all future visits to the affected content and constitutes a cross‑site scripting risk, not just a temporary credential compromise.

Affected Systems

WordPress sites running the Hacklog Remote Attachment plugin version 1.3.2 or older, regardless of the WordPress core version. The plugin is distributed by HuangYe WuDeng and is installed by site administrators who allow users or abusive third parties to add remote attachments.

Risk and Exploitability

The CVSS score of 7.1 signals a high severity, and the EPSS score of under 1% indicates that known exploitation is rare but possible. The flaw is not listed in the CISA KEV catalog, suggesting limited public exploitation. Attackers most likely target sites where the admin or the plugin's attachment endpoint is accessible, and may exploit it by tricking an authenticated user into sending a crafted request. The weakness is a CSRF vector, ordinarily mitigated by anti‑CSRF tokens; absence of such protection enables the attacker to forge the form submission that triggers the stored‑XSS payload.

Generated by OpenCVE AI on April 30, 2026 at 21:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Hacklog Remote Attachment to a version newer than 1.3.2 as soon as a fix becomes available.
  • If an update cannot be applied immediately, disable the plugin to prevent any more attachment submissions until the issue is resolved.
  • Apply a site‑wide CSRF token or re‑authentication check on every form that writes data, and monitor admin activity logs for suspicious attachment uploads.

Generated by OpenCVE AI on April 30, 2026 at 21:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-12011 Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Attachment allows Stored XSS. This issue affects Hacklog Remote Attachment: from n/a through 1.3.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Attachment allows Stored XSS. This issue affects Hacklog Remote Attachment: from n/a through 1.3.2. Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Attachment hacklog-remote-attachment allows Stored XSS.This issue affects Hacklog Remote Attachment: from n/a through <= 1.3.2.
Title WordPress Hacklog Remote Attachment <= 1.3.2 - Cross Site Request Forgery (CSRF) Vulnerability WordPress Hacklog Remote Attachment plugin <= 1.3.2 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 25 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Attachment allows Stored XSS. This issue affects Hacklog Remote Attachment: from n/a through 1.3.2.
Title WordPress Hacklog Remote Attachment <= 1.3.2 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:40.153Z

Reserved: 2025-04-24T14:23:28.785Z

Link: CVE-2025-46530

cve-icon Vulnrichment

Updated: 2025-04-24T19:54:05.275Z

cve-icon NVD

Status : Deferred

Published: 2025-04-24T16:15:44.287

Modified: 2026-04-23T15:30:11.200

Link: CVE-2025-46530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T21:15:06Z

Weaknesses