First published: Thu Jan 16 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Braulio Aquino García Send to Twitter allows Stored XSS.This issue affects Send to Twitter: from n/a through 1.7.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=1.7.2 | ||
WordPress Twitter | <=1.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23691 has been classified as a high severity vulnerability due to its potential for cross-site request forgery and stored cross-site scripting.
To fix CVE-2025-23691, users should update the Send to Twitter plugin to the latest version beyond 1.7.2.
CVE-2025-23691 affects all versions of the Send to Twitter plugin up to and including version 1.7.2.
CVE-2025-23691 is an identified cross-site request forgery (CSRF) vulnerability that can lead to stored XSS attacks.
The vendor of the vulnerable Send to Twitter plugin associated with CVE-2025-23691 is Braulio Aquino García.