Description
Cross-Site Request Forgery (CSRF) vulnerability in merzedes Custom Style custom-style allows Stored XSS.This issue affects Custom Style: from n/a through <= 1.0.
Published: 2025-12-31
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A cross‑site request forgery flaw in the merzedes Custom Style WordPress plugin allows an attacker to submit a forged request that injects malicious HTML or JavaScript into the plugin’s stored styling data. Because the payload is stored, it is rendered on every page that loads the style, enabling the attacker to run arbitrary script in visitors’ browsers, potentially leading to cookie theft, session hijacking, site defacement, or other malicious actions.

Affected Systems

All WordPress sites running the Custom Style plugin version 1.0 or earlier are affected. The plugin is distributed by the vendor merzedes and the vulnerability exists from its first release through, and including, version 1.0.

Risk and Exploitability

The CVSS base score of 7.1 classifies the flaw as high severity, while the EPSS score of less than 1% indicates a very low probability of exploitation at present. The issue is not listed in the CISA KEV catalog, suggesting no known public exploits. The attack requires an authenticated user with permission to modify plugin styles, which limits the attack surface to privileged users but still permits an attacker who can coerce or compromise such a session to permanently embed malicious code for all site visitors.

Generated by OpenCVE AI on April 30, 2026 at 04:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Custom Style plugin to a version newer than 1.0, or uninstall the plugin if an update is unavailable.
  • Restrict access to the plugin’s style‑editing interface so that only site super‑administrators can make changes, reducing the chance of a CSRF request being accepted.
  • Deploy a web application firewall or security plugin that detects and blocks unexpected POST requests to the plugin’s configuration endpoint, and monitor logs for anomalous style modifications.

Generated by OpenCVE AI on April 30, 2026 at 04:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Wolfgang Häfelinger Custom Style allows Stored XSS.This issue affects Custom Style: from n/a through 1.0. Cross-Site Request Forgery (CSRF) vulnerability in merzedes Custom Style custom-style allows Stored XSS.This issue affects Custom Style: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 02 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 06:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Wolfgang Häfelinger Custom Style allows Stored XSS.This issue affects Custom Style: from n/a through 1.0.
Title WordPress Custom Style plugin <= 1.0 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T01:07:30.582Z

Reserved: 2025-06-04T09:42:27.086Z

Link: CVE-2025-49342

cve-icon Vulnrichment

Updated: 2026-01-02T15:20:10.223Z

cve-icon NVD

Status : Deferred

Published: 2025-12-31T06:15:40.517

Modified: 2026-04-23T15:31:30.073

Link: CVE-2025-49342

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T04:45:06Z

Weaknesses