Description
Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-search-and-replace allows Cross Site Request Forgery.This issue affects CM On Demand Search And Replace: from n/a through <= 1.5.2.
Published: 2025-08-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CM On Demand Search And Replace plugin contains a CSRF flaw (CWE‑352) that could allow an attacker to trick a user who is logged into the WordPress site into executing actions the plugin author intended only for an admin interface. Such unintended activity might include arbitrary search‑and‑replace operations that could modify large amounts of content or otherwise interfere with site operation. The CVSS score of 4.3 reflects a moderate risk level, indicating that the flaw can impact the confidentiality or integrity of data depending on how an attacker uses the abused functionality.

Affected Systems

All WordPress installations running CreativeMindsSolutions CM On Demand Search And Replace version 1.5.2 or earlier are potentially affected, encompassing every release from the initial build through the 1.5.2 release.

Risk and Exploitability

The EPSS score of less than 1% suggests that, at present, exploitation is unlikely to be widespread. The flaw is not listed in the CISA KEV catalog, further indicating limited real‑world use. However, CSRF attacks are typically client‑side and require the victim to be logged in and to be directed to a crafted request. Given that the plug‑in’s administrative forms likely do not include robust anti‑CSRF tokens, the risk is moderate; an authenticated user could inadvertently execute privileged actions if no additional safeguards are in place.

Generated by OpenCVE AI on April 30, 2026 at 08:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the plugin to the latest version that eliminates the CSRF vulnerability.
  • Restrict access to the plugin’s administrative interface to administrators or a tightly controlled group of trusted users.
  • If an update cannot be applied immediately, augment the plugin’s forms with WordPress’ built‑in nonce mechanism (wp_nonce_field) or otherwise ensure each request carries a unique CSRF token to verify legitimacy.

Generated by OpenCVE AI on April 30, 2026 at 08:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24911 Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace allows Cross Site Request Forgery. This issue affects CM On Demand Search And Replace: from n/a through 1.5.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace allows Cross Site Request Forgery. This issue affects CM On Demand Search And Replace: from n/a through 1.5.2. Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-search-and-replace allows Cross Site Request Forgery.This issue affects CM On Demand Search And Replace: from n/a through <= 1.5.2.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Sat, 16 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Cminds
Cminds cm On Demand Search And Replace
Cminds cm Search And Replace
Wordpress
Wordpress wordpress
Vendors & Products Cminds
Cminds cm On Demand Search And Replace
Cminds cm Search And Replace
Wordpress
Wordpress wordpress

Thu, 14 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 18:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace allows Cross Site Request Forgery. This issue affects CM On Demand Search And Replace: from n/a through 1.5.2.
Title WordPress CM On Demand Search And Replace Plugin <= 1.5.2 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Cminds Cm On Demand Search And Replace Cm Search And Replace
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:36.872Z

Reserved: 2025-07-28T10:56:33.521Z

Link: CVE-2025-54728

cve-icon Vulnrichment

Updated: 2025-08-14T19:31:13.290Z

cve-icon NVD

Status : Deferred

Published: 2025-08-14T19:15:38.310

Modified: 2026-04-23T15:32:53.827

Link: CVE-2025-54728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T09:00:20Z

Weaknesses