Description
Cross-Site Request Forgery (CSRF) vulnerability in Yaidier WN Flipbox Pro wn-flipbox-pro allows Reflected XSS.This issue affects WN Flipbox Pro: from n/a through <= 2.1.
Published: 2025-09-05
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WN Flipbox Pro WordPress plugin contains a Cross‑Site Request Forgery flaw that permits a malicious actor to craft a request that is processed by the plugin and has part of the payload reflected back to the victim’s browser. This reflected data can include arbitrary JavaScript, enabling Reflected XSS that runs in the context of the user’s session. The vulnerability is based on CWE‑352 and, if exploited, could allow an attacker to execute code in the victim browser or deface the site.

Affected Systems

Any WordPress site that has the Yaidier WN Flipbox Pro plugin installed with a version up to and including 2.1 is vulnerable. No specific operating system or PHP version restrictions are indicated, so any typical WordPress deployment using these plugin releases may be affected.

Risk and Exploitability

The absolute severity of 7.1 on the CVSS V3.1 scale indicates a high impact if used by an attacker, but the EPSS score of less than 1% shows that exploitation in the wild is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, implying that there are no confirmed public exploits. Based on the description, it is inferred that the likely attack vector involves an attacker crafting a malicious link or form that forces a logged‑in user to send a forged request to the plugin, which then processes the request and echoes back the attacker’s payload, resulting in client‑side script execution.

Generated by OpenCVE AI on May 1, 2026 at 06:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WN Flipbox Pro plugin to any version newer than 2.1 to remove the CSRF flaw.
  • If an upgrade is not feasible, remove or uninstall the WN Flipbox Pro plugin from the WordPress installation to eliminate the attack surface.
  • Implement WordPress‑level CSRF protections by ensuring administrative requests use nonces and set the SameSite attribute on relevant cookies to mitigate forged requests.

Generated by OpenCVE AI on May 1, 2026 at 06:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26930 Cross-Site Request Forgery (CSRF) vulnerability in Yaidier WN Flipbox Pro allows Reflected XSS. This issue affects WN Flipbox Pro: from n/a through 2.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Yaidier WN Flipbox Pro allows Reflected XSS. This issue affects WN Flipbox Pro: from n/a through 2.1. Cross-Site Request Forgery (CSRF) vulnerability in Yaidier WN Flipbox Pro wn-flipbox-pro allows Reflected XSS.This issue affects WN Flipbox Pro: from n/a through <= 2.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 05 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Sep 2025 14:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Yaidier WN Flipbox Pro allows Reflected XSS. This issue affects WN Flipbox Pro: from n/a through 2.1.
Title WordPress WN Flipbox Pro Plugin <= 2.1 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-13T00:18:22.320Z

Reserved: 2025-09-05T10:49:49.115Z

Link: CVE-2025-58847

cve-icon Vulnrichment

Updated: 2025-09-05T14:44:14.146Z

cve-icon NVD

Status : Deferred

Published: 2025-09-05T14:15:58.690

Modified: 2026-04-23T15:33:45.007

Link: CVE-2025-58847

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T06:30:10Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)