Description
Cross-Site Request Forgery (CSRF) vulnerability in George Lewe Lewe ChordPress chordpress allows Stored XSS.This issue affects Lewe ChordPress: from n/a through <= 4.0.1.
Published: 2025-06-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Lewe ChordPress plugin permits an attacker to send a forged request that injects arbitrary script code into stored data. This Cross‑Site Request Forgery vulnerability results in Persisted XSS, allowing the attacker to compromise confidentiality and integrity of all users who view the affected content. The weakness is classified as CWE‑352, underscoring a failure to validate the authenticity of state‑changing requests.

Affected Systems

WordPress site running the Lewe ChordPress plugin, versions <=4.0.1. The vulnerability applies to all releases within this range, regardless of minor version differences.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity and the EPSS score of less than 1% suggests a low but non‑zero probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to trick an authenticated user or an attacker’s browser into making the forged request; once the malicious script is stored, any visitor to the affected content will execute it.

Generated by OpenCVE AI on April 30, 2026 at 17:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Lewe ChordPress plugin to the newest available version (greater than 4.0.1).
  • Remove any stored content that may contain injected scripts and regenerate any modified database entries.
  • Ensure that all state‑changing requests in the plugin are protected with proper CSRF tokens or WordPress nonces before processing.

Generated by OpenCVE AI on April 30, 2026 at 17:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28463 Cross-Site Request Forgery (CSRF) vulnerability in George Lewe Lewe ChordPress allows Stored XSS. This issue affects Lewe ChordPress: from n/a through 3.9.7.
History

Thu, 30 Apr 2026 04:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in George Lewe Lewe ChordPress allows Stored XSS. This issue affects Lewe ChordPress: from n/a through 3.9.7. Cross-Site Request Forgery (CSRF) vulnerability in George Lewe Lewe ChordPress chordpress allows Stored XSS.This issue affects Lewe ChordPress: from n/a through <= 4.0.1.
Title WordPress Lewe ChordPress plugin <= 3.9.7 - Cross Site Request Forgery (CSRF) to Stored XSS Vulnerability WordPress Lewe ChordPress plugin <= 4.0.1 - Cross Site Request Forgery (CSRF) to Stored XSS Vulnerability
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 20 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in George Lewe Lewe ChordPress allows Stored XSS. This issue affects Lewe ChordPress: from n/a through 3.9.7.
Title WordPress Lewe ChordPress plugin <= 3.9.7 - Cross Site Request Forgery (CSRF) to Stored XSS Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:19.008Z

Reserved: 2025-06-19T10:03:22.155Z

Link: CVE-2025-52789

cve-icon Vulnrichment

Updated: 2025-06-23T16:13:18.897Z

cve-icon NVD

Status : Deferred

Published: 2025-06-20T15:15:33.950

Modified: 2026-04-23T15:32:10.633

Link: CVE-2025-52789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T17:45:26Z

Weaknesses