First published: Thu Jan 16 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Mukesh Dak MD Custom content after or before of post allows Stored XSS.This issue affects MD Custom content after or before of post: from n/a through 1.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress MD Custom Content After or Before of Post | <=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23463 is rated as a medium severity vulnerability due to its potential for exploitation through Cross-Site Request Forgery leading to Stored XSS.
To mitigate CVE-2025-23463, upgrade the MD Custom content after or before of post plugin to a version above 1.0, or implement security measures to validate requests.
CVE-2025-23463 affects the MD Custom content after or before of post plugin for WordPress versions up to and including 1.0.
CVE-2025-23463 is a Cross-Site Request Forgery (CSRF) vulnerability that can potentially lead to Stored Cross-Site Scripting (XSS).
Yes, a patch is available by updating the MD Custom content after or before of post plugin to the latest version that addresses this vulnerability.