Description
Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak Cool Author Box hm-cool-author-box-widget allows Cross Site Request Forgery.This issue affects Cool Author Box: from n/a through <= 3.0.0.
Published: 2025-05-07
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Cool Author Box plugin for WordPress version 3.0.0 and earlier is vulnerable to cross‑site request forgery. An attacker can force a logged‑in administrator or other privileged user to submit a request that the plugin interprets as a legitimate action, potentially altering plugin settings or site content. This flaw enables unauthorized state changes that could compromise site integrity or allow an attacker to maintain persistence through altered configurations.

Affected Systems

The vulnerability affects the Hossni Mubarak Cool Author Box plugin for WordPress with all versions from the initial release up to and including 3.0.0.

Risk and Exploitability

The overall CVSS score of 4.3 indicates moderate risk. The EPSS score of less than 1% suggests that active exploitation is currently rare, and the vulnerability is not catalogued in the CISA KEV list. The likely attack path requires a user with authenticated privileges to be tricked into visiting a malicious site, so the vector is web‑based CSRF. While the exploitation probability is low, the potential impact on administrative controls warrants timely remediation.

Generated by OpenCVE AI on April 30, 2026 at 20:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Cool Author Box plugin to the latest version
  • If an upgrade is not immediately possible, disable the plugin until a fix is applied
  • Review the WordPress user roles and ensure that only trusted administrators have the capabilities required by the plugin

Generated by OpenCVE AI on April 30, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-13864 Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak Cool Author Box allows Cross Site Request Forgery. This issue affects Cool Author Box: from n/a through 3.0.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak Cool Author Box allows Cross Site Request Forgery. This issue affects Cool Author Box: from n/a through 3.0.0. Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak Cool Author Box hm-cool-author-box-widget allows Cross Site Request Forgery.This issue affects Cool Author Box: from n/a through <= 3.0.0.
Title WordPress Cool Author Box <= 3.0.0 - Cross Site Request Forgery (CSRF) Vulnerability WordPress Cool Author Box plugin <= 3.0.0 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00017}

epss

{'score': 0.0002}


Wed, 07 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 May 2025 14:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak Cool Author Box allows Cross Site Request Forgery. This issue affects Cool Author Box: from n/a through 3.0.0.
Title WordPress Cool Author Box <= 3.0.0 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:40.993Z

Reserved: 2025-05-07T09:38:40.257Z

Link: CVE-2025-47447

cve-icon Vulnrichment

Updated: 2025-05-07T17:21:38.163Z

cve-icon NVD

Status : Deferred

Published: 2025-05-07T15:15:58.770

Modified: 2026-04-23T15:30:13.990

Link: CVE-2025-47447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T20:45:36Z

Weaknesses