CVE-2025-49344: WordPress SensitiveTagCloud plugin <= 1.4.1 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Rene Ade SensitiveTagCloud allows Stored XSS.This issue affects SensitiveTagCloud: from n/a through 1.4.1.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in reneade SensitiveTagCloud sensitive-tag-cloud allows Stored XSS.This issue affects SensitiveTagCloud: from n/a through <= 1.4.1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49344?
CVE-2025-49344 is a medium severity vulnerability due to its potential for Cross-Site Request Forgery (CSRF) leading to Stored XSS.
How do I fix CVE-2025-49344?
To fix CVE-2025-49344, update the SensitiveTagCloud plugin to a version higher than 1.4.1.
What is affected by CVE-2025-49344?
CVE-2025-49344 affects the SensitiveTagCloud plugin for WordPress versions up to and including 1.4.1.
Can CVE-2025-49344 be exploited remotely?
Yes, CVE-2025-49344 can be exploited remotely due to its CSRF nature, allowing attackers to perform actions on behalf of authenticated users.
What are the consequences of CVE-2025-49344?
Exploiting CVE-2025-49344 can lead to Stored XSS, allowing attackers to inject malicious scripts into web pages viewed by users.