CVE-2025-22300: WordPress PixelYourSite plugin <= 10.0.1.2 - Cross Site Request Forgery (CSRF) vulnerability
Published Jan 7, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite PixelYourSite – Your smart PIXEL (TAG) Manager pixelyoursite allows Cross Site Request Forgery.This issue affects PixelYourSite – Your smart PIXEL (TAG) Manager: from n/a through <= 10.0.1.2.
Affected Software
1 affected component
PixelYourSite PixelYourSite<=10.0.1.2
Remediation
Information
Update the WordPress PixelYourSite – Your smart PIXEL (TAG) Manager wordpress plugin to the latest available version (at least 10.0.2).
Event History
Jan 7, 2025
CVE Published
via MITRE·10:49 AM
Data Sourced
via MITRE·10:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-22300?
CVE-2025-22300 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2025-22300?
To fix CVE-2025-22300, update your PixelYourSite plugin to version 10.0.1.3 or later.
3
Which software versions are affected by CVE-2025-22300?
CVE-2025-22300 affects PixelYourSite version 10.0.1.2 and earlier versions.
4
What is the impact of CVE-2025-22300?
The impact of CVE-2025-22300 is that it allows attackers to perform unauthorized actions on behalf of the user.
5
Is there a patch for CVE-2025-22300?
Yes, a patch is available in the form of an update to the PixelYourSite plugin.