Description
Cross-Site Request Forgery (CSRF) vulnerability in NTC WP Page Loading wp-page-loading allows Cross Site Request Forgery.This issue affects WP Page Loading: from n/a through <= 1.0.6.
Published: 2025-06-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The NTC WordPress plugin WP Page Loading contains a Cross‑Site Request Forgery (CSRF) vulnerability in versions up to 1.0.6 that permits an attacker to force a legitimate user to execute unintended requests against the site. This flaw can potentially enable the attacker to alter plugin settings or trigger actions normally performed by the victim, but the CVE description does not enumerate the exact operations or the degree of impact. Based on typical CSRF behavior, it is inferred that any plugin functionality that requires a POST or similar request submitted from the victim’s session may be compromised, though the specific scope remains unspecified.

Affected Systems

The vulnerability affects the WordPress plugin WP Page Loading from NTC, impacting all installations of version 1.0.6 and earlier. No further vendor or version details are provided; any site running a vulnerable instance of the plugin is potentially exposed.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity level, while the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the nature of CSRF, the likely attack vector involves a malicious web page or embedded content that triggers a request within an authenticated user’s session; it is inferred that an attacker would need to convince a user to visit such content, indicating a targeted rather than mass‑applied exploit. The overall risk is therefore confined to users who are logged into a site that hosts the vulnerable plugin.

Generated by OpenCVE AI on May 1, 2026 at 07:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Page Loading plugin to any version newer than 1.0.6.
  • If an upgrade is not possible immediately, temporarily disable the plugin until an official fix is available.
  • Perform a site backup and review access logs for evidence of suspicious activity that might indicate exploitation attempts.

Generated by OpenCVE AI on May 1, 2026 at 07:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17253 Cross-Site Request Forgery (CSRF) vulnerability in NTC WP Page Loading allows Cross Site Request Forgery. This issue affects WP Page Loading: from n/a through 1.0.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in NTC WP Page Loading allows Cross Site Request Forgery. This issue affects WP Page Loading: from n/a through 1.0.6. Cross-Site Request Forgery (CSRF) vulnerability in NTC WP Page Loading wp-page-loading allows Cross Site Request Forgery.This issue affects WP Page Loading: from n/a through <= 1.0.6.
Title WordPress WP Page Loading <= 1.0.6 - Cross Site Request Forgery (CSRF) Vulnerability WordPress WP Page Loading plugin <= 1.0.6 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 06 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 13:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in NTC WP Page Loading allows Cross Site Request Forgery. This issue affects WP Page Loading: from n/a through 1.0.6.
Title WordPress WP Page Loading <= 1.0.6 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:00.805Z

Reserved: 2025-06-04T09:42:07.048Z

Link: CVE-2025-49317

cve-icon Vulnrichment

Updated: 2025-06-06T18:58:59.115Z

cve-icon NVD

Status : Deferred

Published: 2025-06-06T13:15:47.713

Modified: 2026-04-23T15:31:27.257

Link: CVE-2025-49317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T08:00:13Z

Weaknesses