First published: Mon Mar 24 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in karrikas banner-manager allows Stored XSS. This issue affects banner-manager: from n/a through 16.04.19.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Karrikas Banner Manager | <=16.04.19 | |
WordPress Banner Manager | <=16.04.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-30565 is considered high due to its ability to allow Stored XSS through Cross-Site Request Forgery.
To fix CVE-2025-30565, update the karrikas banner-manager plugin to a version beyond 16.04.19.
CVE-2025-30565 can lead to unauthorized actions being performed on behalf of users, compromising their data and security.
CVE-2025-30565 affects all versions of karrikas banner-manager from n/a up to and including 16.04.19.
Website administrators using versions of karrikas banner-manager up to 16.04.19 should be particularly concerned about CVE-2025-30565.