Description
Cross-Site Request Forgery (CSRF) vulnerability in vgstef WP User Stylesheet Switcher wp-user-stylesheet-switcher allows Stored XSS.This issue affects WP User Stylesheet Switcher: from n/a through <= v2.2.0.
Published: 2025-06-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP User Stylesheet Switcher plugin contains a cross‑site request forgery flaw that allows an attacker to cause an authenticated administrator to submit a request that stores malicious JavaScript in the plugin’s settings. Once the injected script is loaded by visitors, it can steal cookies, deface content, or deliver malware. The weakness corresponds to the CWE‑352 "Cross‑Site Request Forgery" enumeration.

Affected Systems

The vulnerable versions are all releases of WP User Stylesheet Switcher from the initial release through v2.2.0, issued by developer vgstef. The plugin is used on WordPress sites to enable per‑user stylesheet selection; any site that has installed these or older plugin versions is affected.

Risk and Exploitability

The CVSS base score of 7.1 signals a high risk, but the EPSS score of less than 1 % indicates that exploitation is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to convince or directly use a user with administrator privileges to trigger the malicious request, making the threat most acute for sites that allow web‑based admin logins.

Generated by OpenCVE AI on April 30, 2026 at 11:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP User Stylesheet Switcher plugin to the latest version (v2.3.0 or later).
  • If a newer version is not available, temporarily disable the plugin to close the attack surface.
  • Continuously monitor site traffic and user activity for signs of injected scripts or unexpected behavior.

Generated by OpenCVE AI on April 30, 2026 at 11:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28467 Cross-Site Request Forgery (CSRF) vulnerability in vgstef WP User Stylesheet Switcher allows Stored XSS. This issue affects WP User Stylesheet Switcher: from n/a through v2.2.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in vgstef WP User Stylesheet Switcher allows Stored XSS. This issue affects WP User Stylesheet Switcher: from n/a through v2.2.0. Cross-Site Request Forgery (CSRF) vulnerability in vgstef WP User Stylesheet Switcher wp-user-stylesheet-switcher allows Stored XSS.This issue affects WP User Stylesheet Switcher: from n/a through <= v2.2.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 20 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in vgstef WP User Stylesheet Switcher allows Stored XSS. This issue affects WP User Stylesheet Switcher: from n/a through v2.2.0.
Title WordPress WP User Stylesheet Switcher plugin <= v2.2.0 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:25:29.263Z

Reserved: 2025-06-19T10:03:22.155Z

Link: CVE-2025-52792

cve-icon Vulnrichment

Updated: 2025-06-23T16:13:34.382Z

cve-icon NVD

Status : Deferred

Published: 2025-06-20T15:15:34.390

Modified: 2026-04-23T15:32:10.973

Link: CVE-2025-52792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T11:15:35Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)