CVE-2025-58676: WordPress HORIZONTAL SLIDER Plugin <= 2.4 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in extendyourweb HORIZONTAL SLIDER allows Stored XSS. This issue affects HORIZONTAL SLIDER: from n/a through 2.4.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in extendyourweb HORIZONTAL SLIDER horizontal-slider allows Stored XSS.This issue affects HORIZONTAL SLIDER: from n/a through <= 2.4.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58676?
CVE-2025-58676 has a severity rating of 7.1, which is classified as high.
How do I fix CVE-2025-58676?
To fix CVE-2025-58676, update the extendyourweb HORIZONTAL SLIDER plugin to version 2.5 or later.
What types of vulnerabilities are associated with CVE-2025-58676?
CVE-2025-58676 is associated with Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS) vulnerabilities.
Which versions of the HORIZONTAL SLIDER plugin are affected by CVE-2025-58676?
CVE-2025-58676 affects the extendyourweb HORIZONTAL SLIDER plugin from versions n/a through 2.4.
What can attackers do with CVE-2025-58676?
Attackers can exploit CVE-2025-58676 to perform Cross-Site Request Forgery, potentially leading to Stored XSS attacks.