First published: Thu Jan 16 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Vinícius Krolow Twitter Post allows Stored XSS.This issue affects Twitter Post: from n/a through 0.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=0.1 | ||
WordPress Twitter Post | <=0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23654 is rated as a moderate severity vulnerability due to the potential for Cross-Site Request Forgery leading to Stored XSS.
To fix CVE-2025-23654, update the Vinícius Krolow Twitter Post or WordPress Twitter Post plugin to a version above 0.1.
CVE-2025-23654 can facilitate Cross-Site Request Forgery attacks that may lead to Stored Cross-Site Scripting (XSS).
CVE-2025-23654 affects Vinícius Krolow Twitter Post and WordPress Twitter Post plugin versions up to 0.1.
The vendor affected by CVE-2025-23654 is Vinícius Krolow for the Twitter Post and WordPress for the Twitter Post plugin.