Description
Cross-Site Request Forgery (CSRF) vulnerability in dyiosah Ultimate twitter profile widget ultimate-twitter-profile-widget allows Stored XSS.This issue affects Ultimate twitter profile widget: from n/a through <= 1.0.
Published: 2025-08-28
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ultimate Twitter Profile Widget plugin contains a Cross‑Site Request Forgery flaw that can be abused to store malicious JavaScript on the website; once injected, the script runs automatically for every visitor, allowing attackers to harvest session cookies, deface content, or execute further malicious actions. This stored XSS attack can compromise confidentiality, integrity, and availability for all users who view affected pages and may also provide a vector for credential theft if an attacker can target logged‑in administrators. The weakness is rooted in improper CSRF protection and insufficient input validation in the plugin's data storage logic, identified as CWE‑352.

Affected Systems

WordPress sites running the Ultimate Twitter Profile Widget by dyiosah at any version up to and including 1.0 are affected; the problem exists in all releases from the initial release through version 1.0, and no later release has been identified as containing a fix.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, but the EPSS score of less than 1 % suggests a very low probability of exploitation in the wild. The issue is not currently listed in the CISA KEV catalog, implying no known widespread exploitation. The attack vector is inferred to require an authenticated user (typically an administrator) to craft a CSRF request that writes the malicious script to the site; once executed, the XSS effect persists for all site visitors. Given the low exploitability metrics, the risk is medium to high if the plugin is actively used by critical sites, especially those where an attacker could influence content for visitors.

Generated by OpenCVE AI on April 30, 2026 at 07:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Ultimate Twitter Profile Widget to the latest version (greater than 1.0) to remove the CSRF vulnerability that facilitates stored XSS.
  • If upgrading is infeasible, permanently disable or uninstall the plugin so that no user input can be abused for stored XSS attacks.
  • Implement a web application firewall rule or content security policy that blocks unexpected script tags or denies execution of inline JavaScript added by the plugin, as a temporary workaround until a patch is available.

Generated by OpenCVE AI on April 30, 2026 at 07:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26038 Cross-Site Request Forgery (CSRF) vulnerability in dyiosah Ultimate twitter profile widget allows Stored XSS. This issue affects Ultimate twitter profile widget: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in dyiosah Ultimate twitter profile widget allows Stored XSS. This issue affects Ultimate twitter profile widget: from n/a through 1.0. Cross-Site Request Forgery (CSRF) vulnerability in dyiosah Ultimate twitter profile widget ultimate-twitter-profile-widget allows Stored XSS.This issue affects Ultimate twitter profile widget: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 28 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in dyiosah Ultimate twitter profile widget allows Stored XSS. This issue affects Ultimate twitter profile widget: from n/a through 1.0.
Title WordPress Ultimate twitter profile widget plugin <= 1.0 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:56.821Z

Reserved: 2025-05-19T14:14:03.305Z

Link: CVE-2025-48321

cve-icon Vulnrichment

Updated: 2025-08-28T13:33:25.645Z

cve-icon NVD

Status : Deferred

Published: 2025-08-28T13:15:49.027

Modified: 2026-04-23T15:31:06.080

Link: CVE-2025-48321

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T08:00:13Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)