First published: Thu Jan 16 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Oren hahiashvili add custom google tag manager allows Stored XSS.This issue affects add custom google tag manager: from n/a through 1.0.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Add Custom Google Tag Manager | >=n/a<1.0.3 | |
Google Tag Manager | <=1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23537 is classified as a high severity Cross-Site Request Forgery vulnerability that can lead to Stored XSS attacks.
To fix CVE-2025-23537, update the Oren Hahiashvili add custom google tag manager plugin to version 1.0.4 or later.
CVE-2025-23537 affects the Oren Hahiashvili add custom google tag manager plugin version up to and including 1.0.3.
CVE-2025-23537 is a Cross-Site Request Forgery (CSRF) vulnerability that additionally allows for Stored Cross-Site Scripting (XSS).
Yes, if your website uses version 1.0.3 or earlier of the Oren Hahiashvili add custom google tag manager plugin, it is vulnerable to CVE-2025-23537.