Description
Cross-Site Request Forgery (CSRF) vulnerability in johnh10 Video Blogster Lite video-blogster-lite allows Stored XSS.This issue affects Video Blogster Lite: from n/a through <= 1.2.
Published: 2025-10-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Video Blogster Lite plugin contains a CSRF flaw that allows an attacker to submit a crafted request on behalf of an authenticated WordPress user. This flaw can be leveraged to inject persistent JavaScript into posts or comments, resulting in stored cross-site scripting. Attackers can use the injected code to steal user cookies, hijack sessions, deface content, or execute arbitrary commands in the context of the blog. Although the vulnerability does not directly grant code execution, the stored XSS capability provides a broad attack surface against site visitors.

Affected Systems

Affected systems are WordPress sites running the johnh10 Video Blogster Lite plugin, version 1.2 or earlier. All installations of the plugin prior to 1.3 are vulnerable. The issue is reported for all unpatched versions up through <=1.2.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact, while the EPSS score of <1% suggests that exploitation attempts are rare to date. The vulnerability is not listed in CISA KEV, so no confirmed active exploitation is known. Because the flaw relies on a CSRF attack vector, an attacker would need to convince a legitimate user to visit a malicious site or click a link that performs the unauthorized action. Once triggered, the stored XSS payload can affect all visitors to the compromised page. Security teams should consider the attack vector as remote, yet the potential damage to site integrity and user trust warrants prompt action.

Generated by OpenCVE AI on April 29, 2026 at 23:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Video Blogster Lite to the latest version that includes the CSRF fix.
  • If an update is unavailable, disable or uninstall the Video Blogster Lite plugin until the issue is resolved.
  • Restrict the plugin’s write capabilities to high-privilege roles only, and ensure that all state-changing requests validate a unique nonce.
  • Monitor site logs for unexpected POST requests to the plugin’s endpoints and alert on suspicious activity.

Generated by OpenCVE AI on April 29, 2026 at 23:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in johnh10 Video Blogster Lite video-blogster-lite allows Stored XSS.This issue affects Video Blogster Lite: from n/a through <= 1.2.
Title WordPress Video Blogster Lite Plugin <= 1.2 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:55.331Z

Reserved: 2025-09-25T15:20:34.879Z

Link: CVE-2025-60132

cve-icon Vulnrichment

Updated: 2025-10-22T19:49:46.173Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:56.897

Modified: 2026-04-27T16:16:32.457

Link: CVE-2025-60132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:45:16Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)