First published: Mon Mar 24 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in bbodine1 cTabs allows Stored XSS. This issue affects cTabs: from n/a through 1.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
bbodine1 cTabs | >=1.3 | |
WordPress cTabs | <=1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30586 has been assigned a moderate severity due to its potential to allow Stored Cross-Site Scripting (XSS) through CSRF attacks.
To mitigate CVE-2025-30586, update to a version of cTabs that is higher than 1.3, as this will address the vulnerability.
The impacts of CVE-2025-30586 include the possibility of attackers executing arbitrary scripts on behalf of authenticated users, leading to unauthorized actions.
CVE-2025-30586 affects users of bbodine1 cTabs versions 1.3 and below, as well as WordPress cTabs versions up to and including 1.3.
CVE-2025-30586 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that leads to Stored Cross-Site Scripting (XSS).