First published: Thu Jan 16 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Joshua Wieczorek Bible Embed allows Stored XSS.This issue affects Bible Embed: from n/a through 0.0.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bible Embed | <=0.0.4 | |
WordPress Bible Embed | <=0.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23513 is rated as a high-severity vulnerability due to its potential for allowing stored cross-site scripting (XSS) via CSRF.
To remediate CVE-2025-23513, upgrade the Joshua Wieczorek Bible Embed or WordPress Bible Embed plugin to a version newer than 0.0.4.
CVE-2025-23513 affects Joshua Wieczorek Bible Embed and WordPress Bible Embed versions up to and including 0.0.4.
CVE-2025-23513 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to stored cross-site scripting (XSS).
Yes, CVE-2025-23513 can be exploited remotely, allowing an attacker to execute scripts in the context of the user's session.