XV Random Quotes WordPress Plugin Cross-Site Request Forgery Vulnerability

Vulnerability

A vulnerability exists in the XV Random Quotes WordPress plugin, versions through 1.40, due to the absence of Cross-Site Request Forgery (CSRF) protection when updating settings. This flaw could enable attackers to exploit a logged-in admin by forcing them to reset plugin settings without their consent.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in plugin settings, potentially disrupting the functionality of the XV Random Quotes plugin or causing other unforeseen issues on the WordPress site.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.