First published: Mon Mar 24 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in mendibass Browser Address Bar Color allows Stored XSS. This issue affects Browser Address Bar Color: from n/a through 3.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30577 is a critical vulnerability due to its potential for Cross-Site Request Forgery (CSRF) leading to Stored XSS.
To fix CVE-2025-30577, update the Browser Address Bar Color plugin to a version higher than 3.3.
CVE-2025-30577 affects Browser Address Bar Color versions up to and including 3.3.
CVE-2025-30577 is a Cross-Site Request Forgery (CSRF) vulnerability that allows Stored XSS.
Users of the Browser Address Bar Color plugin on WordPress who are running version 3.3 or earlier are impacted by CVE-2025-30577.