Description
Cross-Site Request Forgery (CSRF) vulnerability in Yamna Khawaja Mailing Group Listserv wp-mailing-group allows Cross Site Request Forgery.This issue affects Mailing Group Listserv: from n/a through <= 3.0.5.
Published: 2025-06-20
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross–Site Request Forgery flaw in the Mailing Group Listserv plugin that allows an attacker to cause authenticated users to perform actions with permissions they hold. This can result in unintended changes to site or group settings, posting of spam, or modification of subscription lists. The weakness, identified as CWE‑352, enables an attacker to forge requests without the user's consent, effectively escalating privileges within the context of the logged‑in user.

Affected Systems

The security issue affects the WordPress Mailing Group Listserv plugin developed by Yamna Khawaja when installed on any WordPress site. All releases up to and including version 3.0.5 are vulnerable; newer releases are not affected.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector requires a victim to be authenticated to the WordPress site and interact with the plugin’s functionality, typically via a crafted request from a malicious site while the victim is logged in. Based on this description, exploitation would be client‑assisted and would depend on a user visiting a malicious page or click‑through a link targeting the plugin’s endpoints.

Generated by OpenCVE AI on April 30, 2026 at 10:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Mailing Group Listserv plugin to any version higher than 3.0.5 to eliminate the CSRF flaw.
  • If an upgrade is not immediately possible, temporarily deactivate the plugin to remove the vulnerable functionality from the site.
  • Add site‑wide CSRF protection by applying a security plugin that enforces tokens on all forms and AJAX requests, mitigating similar weaknesses in other plugins.
  • Regularly monitor the plugin’s release notes and security advisories, and apply any future patches as soon as they become available.

Generated by OpenCVE AI on April 30, 2026 at 10:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28361 Cross-Site Request Forgery (CSRF) vulnerability in Yamna Khawaja Mailing Group Listserv allows Cross Site Request Forgery. This issue affects Mailing Group Listserv: from n/a through 3.0.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Yamna Khawaja Mailing Group Listserv allows Cross Site Request Forgery. This issue affects Mailing Group Listserv: from n/a through 3.0.5. Cross-Site Request Forgery (CSRF) vulnerability in Yamna Khawaja Mailing Group Listserv wp-mailing-group allows Cross Site Request Forgery.This issue affects Mailing Group Listserv: from n/a through <= 3.0.5.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Mon, 23 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Yamna Khawaja Mailing Group Listserv allows Cross Site Request Forgery. This issue affects Mailing Group Listserv: from n/a through 3.0.5.
Title WordPress Mailing Group Listserv plugin <= 3.0.5 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:16.919Z

Reserved: 2025-06-11T16:08:41.943Z

Link: CVE-2025-50036

cve-icon Vulnrichment

Updated: 2025-06-23T16:11:56.844Z

cve-icon NVD

Status : Deferred

Published: 2025-06-20T15:15:29.837

Modified: 2026-04-23T15:32:01.400

Link: CVE-2025-50036

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T11:00:15Z

Weaknesses