Description
Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework civi-framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through <= 2.1.6.
Published: 2025-06-10
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw is a Cross‑Site Request Forgery that allows an external site to trigger the user deactivation action of the Civi Framework plugin without the victim’s direct interaction. An attacker can construct a malicious request that, when sent from a user who is authenticated to the site, deactivates the user account. As a result, legitimate users or administrators may lose access, potentially disrupting site operation and control. The underlying weakness is CSRF (CWE‑352).

Affected Systems

Systems that host the uxper Civi Framework plugin and run any version up to and including 2.1.6 are impacted. The plugin is distributed by the vendor uxper. All releases of the plugin with a version number of 2.1.6 or earlier are therefore considered vulnerable.

Risk and Exploitability

The CVSS score of 7.1 reflects a high severity, indicating significant impact if exploited. The EPSS score of less than 1% shows that the likelihood of exploitation is presently very low, although non‑zero. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it via a CSRF attack: by luring an authenticated user to a malicious URL or embedding a hidden form, the attacker can cause the deactivation endpoint to be invoked using the victim’s credentials. No elevated privileges beyond those of the authenticated user are required, so the impact can scale from the loss of a single user to the loss of administrative control if an admin account is deactivated.

Generated by OpenCVE AI on April 30, 2026 at 17:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Civi Framework plugin to a version newer than 2.1.6 to apply the vendor’s CSRF protection fix.
  • If an upgrade cannot be performed immediately, restrict the deactivation endpoint so that only administrators can access it and enforce CSRF token validation or block requests whose origin is not trusted.
  • Disable or uninstall the Civi Framework plugin until a patched version is available, thereby removing the vulnerable functionality from the attack surface.
  • Deploy web application firewall rules or monitor logs to detect and block suspicious deactivation attempts.

Generated by OpenCVE AI on April 30, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17670 Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6. Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework civi-framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through <= 2.1.6.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00017}

epss

{'score': 0.00018}


Tue, 10 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Jun 2025 13:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.
Title WordPress Civi Framework plugin <= 2.1.6 - Cross Site Request Forgery (CSRF) to User Deactivation vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:05.603Z

Reserved: 2025-06-06T10:33:37.437Z

Link: CVE-2025-49511

cve-icon Vulnrichment

Updated: 2025-06-10T13:47:23.404Z

cve-icon NVD

Status : Deferred

Published: 2025-06-10T13:15:23.747

Modified: 2026-04-23T15:31:43.440

Link: CVE-2025-49511

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T18:00:14Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)