First published: Thu Jan 16 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Pascal Casier Board Election allows Stored XSS.This issue affects Board Election: from n/a through 1.0.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pascal Casier Board Election | >n/a<=1.0.1 | |
WordPress BEAR Plugin | <=1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23499 has a moderate severity level due to its potential for exploitation through cross-site request forgery leading to stored XSS.
To fix CVE-2025-23499, update the Pascal Casier Board Election software to version 1.0.2 or later.
CVE-2025-23499 affects Pascal Casier Board Election up to version 1.0.1 and the WordPress Board Election plugin versions up to 1.0.1.
CVE-2025-23499 allows an attacker to execute cross-site request forgery that could lead to stored cross-site scripting attacks.
There are currently no publicly known exploits specifically for CVE-2025-23499, but its nature makes it potential for abuse if unpatched.