First published: Mon Mar 24 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Igor Yavych Simple Rating allows Stored XSS. This issue affects Simple Rating: from n/a through 1.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Simple Rating | >=1.4 | |
Igor Yavych Simple Rating | <=1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30572 has a medium severity rating due to its potential for Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) issues.
To fix CVE-2025-30572, you should upgrade the Simple Rating plugin to version 1.5 or later to mitigate the vulnerability.
CVE-2025-30572 allows attackers to perform Cross-Site Request Forgery attacks that may result in Stored XSS vulnerabilities.
CVE-2025-30572 affects all versions of Simple Rating from n/a up to version 1.4.
The vendor of the affected software for CVE-2025-30572 is Igor Yavych.