First published: Thu Apr 24 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Attachment allows Stored XSS. This issue affects Hacklog Remote Attachment: from n/a through 1.3.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Hacklog Remote Attachment | <=1.3.2 | |
Hacklog Remote Attachment | <=1.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46530 is a high-severity Cross-Site Request Forgery (CSRF) vulnerability that allows for potential Stored XSS.
To fix CVE-2025-46530, update Hacklog Remote Attachment to version 1.3.3 or later.
CVE-2025-46530 affects all versions of Hacklog Remote Attachment up to and including 1.3.2.
CVE-2025-46530 can be exploited to perform Cross-Site Request Forgery (CSRF) attacks that may lead to Stored XSS.
You should check HuangYe WuDeng Hacklog Remote Attachment and WordPress Hacklog Remote Attachment versions up to 1.3.2 for CVE-2025-46530 vulnerabilities.