Description
Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus – Supports Unlimited Channels allows Cross Site Request Forgery. This issue affects WP Discord Post Plus – Supports Unlimited Channels: from n/a through 1.0.2.
Published: 2025-08-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic CSRF flaw identified as CWE‑352 that allows an attacker to forge form submissions or API calls to the plugin while a legitimate user is authenticated. This could let the attacker trigger plugin‑specific actions, such as posting content to Discord channels, execute administrative commands, or otherwise influence the WordPress site in ways that the original user could do. The design of the plugin exposes these sensitive operations without verifying an honest request origin, leaving them open to exploitation during a user session.

Affected Systems

The affected product is the WordPress plugin WP Discord Post Plus – Supports Unlimited Channels, released by wptasker. All installations running version 1.0.2 or earlier are vulnerable; versions prior to 1.0.2 are also affected, though the specific starting version is not disclosed. The plugin runs within any WordPress installation that has it installed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity; however, the EPSS score of less than 1% suggests that, at the time of analysis, the likelihood of public exploitation is low. Attackers would need to lure an authenticated user to visit a malicious URL or submit a crafted form targeting the plugin’s endpoints, which is inferred from the described CSRF flaw. The likely attack vector involves a crafted URL or form submission that the authenticated user might be tricked into executing while logged into WordPress. The vulnerability is not listed in the CISA KEV catalog, indicating no widespread or confirmed exploitation events have been reported. Despite the low exploitation probability, the consequences if exploited could impact the confidentiality and integrity of site content, warranting timely remediation.

Generated by OpenCVE AI on April 30, 2026 at 15:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Discord Post Plus – Supports Unlimited Channels plugin to the latest released version that eliminates the CSRF flaw
  • If upgrading is not immediately possible, disable the plugin or restrict its use to a minimal set of trusted administrator accounts
  • Add or enable WordPress nonces for all plugin forms and AJAX endpoints to provide an additional defense against CSRF

Generated by OpenCVE AI on April 30, 2026 at 15:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28331 Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus &#8211; Supports Unlimited Channels allows Cross Site Request Forgery. This issue affects WP Discord Post Plus &#8211; Supports Unlimited Channels: from n/a through 1.0.2.
History

Tue, 28 Apr 2026 19:45:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in wptasker School Management school-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects School Management: from n/a through <= 93.1.0. Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus – Supports Unlimited Channels allows Cross Site Request Forgery. This issue affects WP Discord Post Plus – Supports Unlimited Channels: from n/a through 1.0.2.
Title WordPress School Management Plugin <= 93.1.0 - Insecure Direct Object References (IDOR) Vulnerability WordPress WP Discord Post Plus – Supports Unlimited Channels plugin <= 1.0.2 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Thu, 23 Apr 2026 15:45:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus &#8211; Supports Unlimited Channels allows Cross Site Request Forgery. This issue affects WP Discord Post Plus &#8211; Supports Unlimited Channels: from n/a through 1.0.2. Authorization Bypass Through User-Controlled Key vulnerability in wptasker School Management school-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects School Management: from n/a through <= 93.1.0.
Title WordPress WP Discord Post Plus – Supports Unlimited Channels plugin <= 1.0.2 - Cross Site Request Forgery (CSRF) vulnerability WordPress School Management Plugin <= 93.1.0 - Insecure Direct Object References (IDOR) Vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 20 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus &#8211; Supports Unlimited Channels allows Cross Site Request Forgery. This issue affects WP Discord Post Plus &#8211; Supports Unlimited Channels: from n/a through 1.0.2.
Title WordPress WP Discord Post Plus – Supports Unlimited Channels plugin <= 1.0.2 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:07.331Z

Reserved: 2025-06-11T16:06:34.446Z

Link: CVE-2025-49896

cve-icon Vulnrichment

Updated: 2025-08-20T14:04:43.758Z

cve-icon NVD

Status : Deferred

Published: 2025-08-20T08:15:39.177

Modified: 2026-04-28T19:33:11.370

Link: CVE-2025-49896

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T16:00:13Z

Weaknesses