PT-2025-7229 · What3Words · What3Words Address Field

·

CVE-2025-26768

·

Published

2025-02-16

·

Updated

2025-02-18

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: what3words Address Field versions n/a through 4.0.15
Description: The issue is a Cross-Site Request Forgery (CSRF) vulnerability that allows Stored XSS in the what3words Address Field. This means an attacker can perform unauthorized actions on a user's account by tricking the user into performing a specific action, and also store malicious scripts that can be executed by other users.
Recommendations: For versions n/a through 4.0.15, update to a version later than 4.0.15 to resolve the issue. As a temporary workaround, consider disabling the what3words Address Field function until a patch is available. Restrict access to the what3words Address Field module to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-26768

Affected Products

What3Words Address Field