First published: Fri Feb 07 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in LukaszWiecek Smart DoFollow allows Stored XSS. This issue affects Smart DoFollow: from n/a through 1.0.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Smart DoFollow | >=n/a<1.0.2 | |
Smart DoFollow | <=1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25152 is classified as a critical severity vulnerability that allows for Stored XSS through CSRF.
To fix CVE-2025-25152, update the Smart DoFollow plugin to version 1.0.3 or later.
CVE-2025-25152 is a Cross-Site Request Forgery (CSRF) vulnerability that leads to Stored XSS.
CVE-2025-25152 affects Smart DoFollow versions from n/a to 1.0.2.
Yes, CVE-2025-25152 can be exploited remotely, allowing attackers to execute scripts in the context of the victim's session.