Description
Cross-Site Request Forgery (CSRF) vulnerability in puravida1976 ShrinkTheWeb (STW) Website Previews shrinktheweb-website-preview-plugin allows Stored XSS.This issue affects ShrinkTheWeb (STW) Website Previews: from n/a through <= 2.8.5.
Published: 2025-09-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ShrinkTheWeb (STW) Website Previews plugin suffers a CSRF flaw that permits an attacker to inject arbitrary JavaScript code into the site's storage layer. When a victim loads a crafted request, the plugin stores the malicious payload, resulting in a stored XSS condition that is later executed whenever a user views stored content. This enables an attacker to deface the site, steal credentials, or perform other malicious actions in the context of legitimate visitors.

Affected Systems

All WordPress installations that run the ShrinkTheWeb (STW) Website Previews plugin from puravida1976 up to and including version 2.8.5 are affected. No specific WordPress core version is mentioned; the vulnerability applies to any instance where the plugin’s vulnerable code is present.

Risk and Exploitability

The CVSS score of 7.1 signals a high severity, and the EPSS score is reported as < 1%, indicating that exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog, so no confirmed active exploits are known. The attack vector appears to be CSRF, requiring a victim to trigger a constructed request that the plugin processes without proper authentication or nonce validation. If successfully exploited, the attacker can store malicious scripts that affect all users who subsequently view the stored content. The combination of high severity and even a low exploitation probability warrants immediate remediation.

Generated by OpenCVE AI on April 30, 2026 at 01:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ShrinkTheWeb (STW) Website Previews to a version newer than 2.8.5 or remove the plugin if it is no longer required.
  • If an upgrade is not feasible, restrict the endpoint that processes the CSRF request by enforcing a WordPress nonce or by configuration through a security plugin that adds CSRF protection to the admin area.
  • Apply a Content Security Policy that forbids inline script execution or restricts script sources to mitigate the impact of any residual stored XSS.

Generated by OpenCVE AI on April 30, 2026 at 01:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30537 Cross-Site Request Forgery (CSRF) vulnerability in puravida1976 ShrinkTheWeb (STW) Website Previews allows Stored XSS. This issue affects ShrinkTheWeb (STW) Website Previews: from n/a through 2.8.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in puravida1976 ShrinkTheWeb (STW) Website Previews allows Stored XSS. This issue affects ShrinkTheWeb (STW) Website Previews: from n/a through 2.8.5. Cross-Site Request Forgery (CSRF) vulnerability in puravida1976 ShrinkTheWeb (STW) Website Previews shrinktheweb-website-preview-plugin allows Stored XSS.This issue affects ShrinkTheWeb (STW) Website Previews: from n/a through <= 2.8.5.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 23 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in puravida1976 ShrinkTheWeb (STW) Website Previews allows Stored XSS. This issue affects ShrinkTheWeb (STW) Website Previews: from n/a through 2.8.5.
Title WordPress ShrinkTheWeb (STW) Website Previews Plugin <= 2.8.5 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-13T10:37:32.379Z

Reserved: 2025-09-03T09:03:46.831Z

Link: CVE-2025-58677

cve-icon Vulnrichment

Updated: 2025-09-23T13:59:17.114Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:16:18.980

Modified: 2026-04-23T15:33:34.673

Link: CVE-2025-58677

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T02:00:13Z

Weaknesses