Description
Cross-Site Request Forgery (CSRF) vulnerability in PluginsPoint Kento Splash Screen kento-splash-screen allows Stored XSS.This issue affects Kento Splash Screen: from n/a through <= 1.4.
Published: 2025-08-28
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cross‑Site Request Forgery in the Kento Splash Screen WordPress plugin lets an attacker make the site store arbitrary JavaScript. The vulnerability is a CSRF flaw that, when triggered, results in a persistent XSS payload. Any subsequent visitor to the site will execute the script in their browser, leading to potential credential theft, site defacement, or lateral movement within the web application. The flaw is classified as CWE‑352, highlighting insufficient request validation.

Affected Systems

The plugin is sold by PluginsPoint as the Kento Splash Screen add‑on for WordPress. All editions from the first release up to and including version 1.4 are affected. Developers and site administrators using any of those versions should review and remediate accordingly.

Risk and Exploitability

With a CVSS score of 7.1, the vulnerability carries a medium‑high severity. Its EPSS score of less than 1 % indicates a low probability of exploitation in the near term, and it is not listed in the CISA KEV catalog. Nevertheless, the flaw permits an attacker to inject malicious code that is stored and then served to every visitor, creating a persistent threat. The most likely exploitation path involves a malicious link or payload that forces an authenticated administrator or privileged user to submit a forged request, after which the script is persisted and subsequently delivered to all site visitors.

Generated by OpenCVE AI on April 30, 2026 at 15:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Kento Splash Screen plugin to a version newer than 1.4 that contains the CSRF protection fix.
  • If an upgrade cannot be performed immediately, remove or deactivate the plugin to eliminate the vector until a patch is available.
  • Apply site‑wide CSRF safeguards such as WordPress core nonce verification or a security plugin that enforces unique tokens, and restrict administrative access to trusted accounts exclusively.

Generated by OpenCVE AI on April 30, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26027 Cross-Site Request Forgery (CSRF) vulnerability in PluginsPoint Kento Splash Screen allows Stored XSS. This issue affects Kento Splash Screen: from n/a through 1.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in PluginsPoint Kento Splash Screen allows Stored XSS. This issue affects Kento Splash Screen: from n/a through 1.4. Cross-Site Request Forgery (CSRF) vulnerability in PluginsPoint Kento Splash Screen kento-splash-screen allows Stored XSS.This issue affects Kento Splash Screen: from n/a through <= 1.4.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 28 Aug 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 28 Aug 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in PluginsPoint Kento Splash Screen allows Stored XSS. This issue affects Kento Splash Screen: from n/a through 1.4.
Title WordPress Kento Splash Screen plugin <= 1.4 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:57.300Z

Reserved: 2025-05-19T14:41:42.786Z

Link: CVE-2025-48351

cve-icon Vulnrichment

Updated: 2025-08-28T17:39:39.769Z

cve-icon NVD

Status : Deferred

Published: 2025-08-28T13:15:54.733

Modified: 2026-04-23T15:31:09.667

Link: CVE-2025-48351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T15:45:40Z

Weaknesses