
Cloud Vulnerability DB
A community-led vulnerabilities database
The Browser Sniff plugin for WordPress contains a Cross-Site Request Forgery (CSRF) vulnerability that can lead to Stored Cross-Site Scripting (XSS) in all versions up to and including 2.3. The vulnerability was discovered and disclosed on September 19, 2025, with the plugin being temporarily closed on September 17, 2025, pending a full security review (Wordfence Intel, WordPress Plugin).
The vulnerability has been assigned a CVSS score of 6.1 (Medium severity). The security researcher johska identified this vulnerability which combines CSRF and Stored XSS attack vectors (Wordfence Intel).
The combination of CSRF and Stored XSS vulnerabilities could allow attackers to execute malicious scripts in users' browsers, potentially leading to unauthorized actions and data theft when users visit affected WordPress sites running the vulnerable Browser Sniff plugin (Wordfence Intel).
As a mitigation measure, the plugin has been temporarily closed and is no longer available for download from the WordPress plugin repository as of September 17, 2025, pending a complete security review (WordPress Plugin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."