Description
Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Cross Site Request Forgery.This issue affects Everest Backup: from n/a through <= 2.3.3.
Published: 2025-06-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE identifies a Cross‑Site Request Forgery vulnerability (CWE‑352) in the Everest Backup plugin for WordPress. According to the description, the flaw enables a malicious actor to cause an authenticated administrator to unknowingly submit a request that performs an unintended action within the plugin. The impact is confined to the administrative actions that the user is authorized to perform; the flaw does not grant remote code execution or overt data exfiltration. It is inferred from the wording that configuration changes or data exposure could result, though the CVE does not detail specific affected functions.

Affected Systems

The affected product is the Everest Backup plugin developed by EverestThemes for WordPress. All releases up to and including version 2.3.3 are impacted, as the description lists “n/a through <= 2.3.3.” Any WordPress site running a vulnerable version within that range is at risk.

Risk and Exploitability

The CVSS base score of 4.3 indicates a medium risk level. The EPSS score of less than 1% shows that widespread exploitation is considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a malicious website or injected content that issues a forged request while an authenticated administrator is browsing the site; the attacker must craft the request and the victim must be logged in. Because the flaw requires an authenticated session and does not involve privilege escalation, the overall risk is moderate and exploitability realistic only in environments with a sizable administrator user base.

Generated by OpenCVE AI on May 1, 2026 at 07:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Everest Backup plugin to a version newer than 2.3.3, which removes the CF‑CSRF flaw.
  • If an update is not available or cannot be applied immediately, consider disabling or uninstalling the plugin until a patched version is released.
  • Implement stricter authentication controls for administrator accounts, such as two‑factor authentication, and limit the number of users with administrative privileges.

Generated by OpenCVE AI on May 1, 2026 at 07:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17295 Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup allows Cross Site Request Forgery. This issue affects Everest Backup: from n/a through 2.3.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup allows Cross Site Request Forgery. This issue affects Everest Backup: from n/a through 2.3.3. Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Cross Site Request Forgery.This issue affects Everest Backup: from n/a through <= 2.3.3.
Title WordPress Everest Backup <= 2.3.3 - Cross Site Request Forgery (CSRF) Vulnerability WordPress Everest Backup plugin <= 2.3.3 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 06 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 13:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup allows Cross Site Request Forgery. This issue affects Everest Backup: from n/a through 2.3.3.
Title WordPress Everest Backup <= 2.3.3 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Everestthemes Everest Backup
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:21:51.385Z

Reserved: 2025-06-04T09:40:52.585Z

Link: CVE-2025-49238

cve-icon Vulnrichment

Updated: 2025-06-06T15:41:00.690Z

cve-icon NVD

Status : Deferred

Published: 2025-06-06T13:15:41.173

Modified: 2026-04-23T15:31:18.043

Link: CVE-2025-49238

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T08:00:13Z

Weaknesses