PT-2025-44960 · Mahype+1 · Pagerank Tools
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pagerank Tools versions prior to 1.1.6
Description
The plugin is subject to Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF). This occurs because the
pr save settings() function lacks nonce validation—a security token used to ensure requests are intentional—and fails to properly sanitize input. Unauthenticated attackers can exploit this by tricking a site administrator into clicking a malicious link, allowing the injection of scripts that execute when the settings page is accessed.Recommendations
Update the plugin to a version newer than 1.1.5.
As a temporary mitigation, restrict access to the plugin settings page to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pagerank Tools