Description
Cross-Site Request Forgery (CSRF) vulnerability in pl4g4 WP-Database-Optimizer-Tools wp-database-optimizer-tools allows Cross Site Request Forgery.This issue affects WP-Database-Optimizer-Tools: from n/a through <= 0.2.
Published: 2025-08-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP-Database-Optimizer-Tools plugin up to version 0.2 contains a Cross‑Site Request Forgery vulnerability that allows an attacker to perform actions defined by the plugin without the user’s consent. The weakness, identified as CWE‑352, means that an unauthenticated attacker could trick a logged‑in administrator into executing a malicious request that modifies or optimizes the WordPress database, potentially leading to data loss or corruption. This represents a moderate security risk because the attacker must exploit the plugin interfaces but does not require more privileged access.

Affected Systems

The vulnerability affects all releases of WP‑Database‑Optimizer‑Tools by pl4g4 that are version 0.2 or earlier. No specific sub‑release information is supplied, so any install of the plugin in this range is considered vulnerable.

Risk and Exploitability

The CVSS score of 5.4 indicates a medium severity, and the EPSS score of less than 1% suggests that exploitation is considered unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve a victim who has administrative rights to the WordPress site being tricked into visiting a malicious website that submits a forged request. The attacker benefits from the victim’s authenticated session, and a successful forgery could read or alter database contents. No active exploits have been reported, so the risk is primarily theoretical but remains present if the plugin is kept in the vulnerable state.

Generated by OpenCVE AI on April 30, 2026 at 08:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP‑Database‑Optimizer‑Tools to a version higher than 0.2 or a patched release.
  • If an upgrade is not possible, disable or uninstall the plugin to eliminate the exposed CSRF surface.
  • Review remaining plugin endpoints for proper non‑ce token validation or access controls before use.

Generated by OpenCVE AI on April 30, 2026 at 08:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24892 Cross-Site Request Forgery (CSRF) vulnerability in pl4g4 WP-Database-Optimizer-Tools allows Cross Site Request Forgery. This issue affects WP-Database-Optimizer-Tools: from n/a through 0.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in pl4g4 WP-Database-Optimizer-Tools allows Cross Site Request Forgery. This issue affects WP-Database-Optimizer-Tools: from n/a through 0.2. Cross-Site Request Forgery (CSRF) vulnerability in pl4g4 WP-Database-Optimizer-Tools wp-database-optimizer-tools allows Cross Site Request Forgery.This issue affects WP-Database-Optimizer-Tools: from n/a through <= 0.2.
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Fri, 15 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Pl4g4
Pl4g4 wp-database-optimizer-tools
Wordpress
Wordpress wordpress
Vendors & Products Pl4g4
Pl4g4 wp-database-optimizer-tools
Wordpress
Wordpress wordpress

Thu, 14 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 18:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in pl4g4 WP-Database-Optimizer-Tools allows Cross Site Request Forgery. This issue affects WP-Database-Optimizer-Tools: from n/a through 0.2.
Title WordPress WP-Database-Optimizer-Tools Plugin <= 0.2 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Subscriptions

Pl4g4 Wp-database-optimizer-tools
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:20.827Z

Reserved: 2025-06-27T10:27:53.889Z

Link: CVE-2025-53219

cve-icon Vulnrichment

Updated: 2025-08-14T20:07:24.809Z

cve-icon NVD

Status : Deferred

Published: 2025-08-14T19:15:34.590

Modified: 2026-04-23T15:32:18.750

Link: CVE-2025-53219

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T09:00:20Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)