Description
Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base – Knowledge Base Maker knowledge-base-maker allows Stored XSS.This issue affects Knowledge Base – Knowledge Base Maker: from n/a through <= 1.1.8.
Published: 2025-06-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw that allows malicious input to be stored and later executed as script within the admin interface. The attacker injects JavaScript that is persisted in the Knowledge Base Maker plugin’s data store, enabling the script to run whenever an authenticated administrator views the affected page. Consequently, the attacker can exfiltrate credentials or other sensitive data, or perform actions on the site using the victim’s privileges. The primary weakness is the lack of proper request validation (CWE‑352).

Affected Systems

WordPress sites that have installed the devfelixmoira Knowledge Base – Knowledge Base Maker plugin version 1.1.8 or earlier are vulnerable. The plugin is a WordPress extension designed to manage a knowledge base; the vendor’s CNA lists the affected range as all releases up to 1.1.8 inclusive.

Risk and Exploitability

The CVSS score of 7.1 classifies this as a high‑severity flaw. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread attacks. However, the attack vector is inferred to require an authenticated administrator who visits a maliciously crafted URL that triggers the CSRF and writes the payload into the store. Once the payload is stored, the risk escalates because any subsequent administrative activity will execute the malicious script, exposing the site to further compromise.

Generated by OpenCVE AI on April 30, 2026 at 11:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Knowledge Base – Knowledge Base Maker plugin to the latest release that removes the CSRF validation flaw.
  • If an upgrade is not immediately possible, uninstall or disable the plugin to prevent execution of stored malicious scripts.

Generated by OpenCVE AI on April 30, 2026 at 11:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28466 Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base &#8211; Knowledge Base Maker allows Stored XSS. This issue affects Knowledge Base &#8211; Knowledge Base Maker: from n/a through 1.1.8.
History

Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base &#8211; Knowledge Base Maker knowledge-base-maker allows Stored XSS.This issue affects Knowledge Base &#8211; Knowledge Base Maker: from n/a through <= 1.1.8. Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base – Knowledge Base Maker knowledge-base-maker allows Stored XSS.This issue affects Knowledge Base – Knowledge Base Maker: from n/a through <= 1.1.8.

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base &#8211; Knowledge Base Maker allows Stored XSS. This issue affects Knowledge Base &#8211; Knowledge Base Maker: from n/a through 1.1.8. Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base &#8211; Knowledge Base Maker knowledge-base-maker allows Stored XSS.This issue affects Knowledge Base &#8211; Knowledge Base Maker: from n/a through <= 1.1.8.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 24 Jun 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base &#8211; Knowledge Base Maker allows Stored XSS. This issue affects Knowledge Base &#8211; Knowledge Base Maker: from n/a through 1.1.8.
Title WordPress Knowledge Base – Knowledge Base Maker plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:19.107Z

Reserved: 2025-06-19T10:03:22.155Z

Link: CVE-2025-52791

cve-icon Vulnrichment

Updated: 2025-06-23T16:13:29.347Z

cve-icon NVD

Status : Deferred

Published: 2025-06-20T15:15:34.247

Modified: 2026-04-28T19:33:27.460

Link: CVE-2025-52791

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T11:15:35Z

Weaknesses