First published: Tue Mar 11 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in DevriX Hashtags allows Stored XSS. This issue affects Hashtags: from n/a through 0.3.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
DevriX Hashtags | <=0.3.2 | |
WordPress Hashtags plugin | <=0.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-28931 is considered a high severity Cross-Site Request Forgery (CSRF) vulnerability.
To fix CVE-2025-28931, update your DevriX Hashtags or WordPress Hashtags plugin to a version later than 0.3.2.
CVE-2025-28931 affects all versions of DevriX Hashtags and WordPress Hashtags plugin from 0.3.2 and earlier.
CVE-2025-28931 is a Cross-Site Request Forgery (CSRF) vulnerability that allows for Stored XSS.
Yes, CVE-2025-28931 can potentially lead to data breaches due to Stored XSS exploitation.