The Limit Bio WordPress plugin through 1.0 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Apr 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Rivercitygraphix
Rivercitygraphix limit Bio |
|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:rivercitygraphix:limit_bio:1.0:*:*:*:*:wordpress*:*:* | |
Vendors & Products |
Rivercitygraphix
Rivercitygraphix limit Bio |
Fri, 14 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 13 Mar 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Limit Bio WordPress plugin through 1.0 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
Title | Limit Bio <= 1.0 - Stored XSS via CSRF | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-03-13T06:00:07.220Z
Updated: 2025-03-14T16:05:53.487Z
Reserved: 2025-02-18T15:01:48.073Z
Link: CVE-2025-1436

Updated: 2025-03-14T16:05:39.456Z

Status : Analyzed
Published: 2025-03-13T06:15:37.077
Modified: 2025-04-29T14:31:36.147
Link: CVE-2025-1436

No data.