PT-2025-44960 · Mahype+1 · Pagerank Tools

·

CVE-2025-12416

·

Published

2025-11-03

·

Updated

2025-11-04

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pagerank Tools versions prior to 1.1.6
Description The plugin is subject to Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF). This occurs because the pr save settings() function lacks nonce validation—a security token used to ensure requests are intentional—and fails to properly sanitize input. Unauthenticated attackers can exploit this by tricking a site administrator into clicking a malicious link, allowing the injection of scripts that execute when the settings page is accessed.
Recommendations Update the plugin to a version newer than 1.1.5. As a temporary mitigation, restrict access to the plugin settings page to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12416

Affected Products

Pagerank Tools