First published: Tue Jan 07 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Ofek Nakar Virtual Bot allows Stored XSS.This issue affects Virtual Bot: from n/a through 1.0.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ofek Nakar Virtual Bot | <=1.0.0 | |
WordPress Virtual Bot Plugin | <=1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22538 is considered a high severity vulnerability due to its potential to allow Cross-Site Request Forgery (CSRF) and Stored XSS attacks.
To fix CVE-2025-22538, update the Ofek Nakar Virtual Bot and WordPress Virtual Bot Plugin to the latest version beyond 1.0.0.
CVE-2025-22538 is a Cross-Site Request Forgery (CSRF) vulnerability that allows a Stored XSS exploit.
CVE-2025-22538 affects versions of Ofek Nakar Virtual Bot and WordPress Virtual Bot Plugin up to and including 1.0.0.
The vendor for CVE-2025-22538 is Ofek Nakar, responsible for the Virtual Bot and the associated vulnerabilities.