Description
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Giveaways and Contests by RafflePress rafflepress allows Cross Site Request Forgery.This issue affects Giveaways and Contests by RafflePress: from n/a through <= 1.12.20.
Published: 2025-11-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cross-Site Request Forgery (CSRF) vulnerability in the WordPress plugin Giveaways and Contests by RafflePress allows an attacker to perform state‑changing actions on behalf of an authenticated user without their consent. The flaw stems from missing or insufficient CSRF token verification when processing form submissions. An attacker can craft a malicious link or form that, if a legitimate user visits the link while authenticated, will trigger unintended modifications or actions within the contest plugin, potentially affecting the visibility or outcome of giveaways. While the vulnerability does not directly expose sensitive data, it could be leveraged to manipulate contest settings, alter participant lists, or inject new promoters, thereby undermining the integrity and trust in the platform.

Affected Systems

The affected product is Syed Balkhi’s Giveaways and Contests by RafflePress plugin for WordPress. All installed copies of the plugin with versions n/a through 1.12.20 are vulnerable, including 1.12.20 and any earlier releases.

Risk and Exploitability

The CVSS score of 4.3 places the issue in the moderate range. The EPSS score of less than 1% indicates a very low probability of current exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to obtain a victim’s authenticated session to exploit the flaw, so the attack vector is inferred as remote via malicious crafted URLs or HTML forms. Given the limited exploitability and lack of public exploits, the overall threat is moderate but should be remediated promptly to prevent potential abuse.

Generated by OpenCVE AI on April 29, 2026 at 20:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Giveaways and Contests by RafflePress plugin to the latest available version, preferably 1.12.21 or later.
  • Verify that the plugin’s form handling now includes proper CSRF token validation; if not, apply a custom patch that enforces token checking for all state‑changing actions.
  • Implement a Web Application Firewall rule or use a WordPress security plugin to block suspicious cross‑site requests targeting the plugin’s endpoints.

Generated by OpenCVE AI on April 29, 2026 at 20:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Rafflepress
Rafflepress giveaways And Contests
Rafflepress giveaways And Contests By Rafflepress
Wordpress
Wordpress wordpress
Vendors & Products Rafflepress
Rafflepress giveaways And Contests
Rafflepress giveaways And Contests By Rafflepress
Wordpress
Wordpress wordpress

Fri, 21 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Nov 2025 12:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Giveaways and Contests by RafflePress rafflepress allows Cross Site Request Forgery.This issue affects Giveaways and Contests by RafflePress: from n/a through <= 1.12.20.
Title WordPress Giveaways and Contests by RafflePress plugin <= 1.12.20 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

Rafflepress Giveaways And Contests Giveaways And Contests By Rafflepress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:15.601Z

Reserved: 2025-11-21T11:20:46.955Z

Link: CVE-2025-66064

cve-icon Vulnrichment

Updated: 2025-11-21T18:46:13.583Z

cve-icon NVD

Status : Deferred

Published: 2025-11-21T13:15:47.337

Modified: 2026-04-27T18:16:32.423

Link: CVE-2025-66064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T20:15:19Z

Weaknesses