CVE-2025-23627

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23627 is a newly disclosed vulnerability affecting the Gordon French Comment-Emailer plugin. This issue combines Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS) weaknesses. An attacker can exploit the CSRF vulnerability to execute malicious scripts on a user's browser by crafting specially designed requests. The Stored XSS component allows the attacker to inject and save malicious code in the comments section, which can be later executed on other users' browsers when they view the affected comments. The vulnerability spans from an unspecified version up to 1.0.5.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share