๐Ÿ” CVE Alert

CVE-2025-23577

UNKNOWN 0.0

WordPress Word Freshener plugin <= 1.3 - CSRF to Stored XSS vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Cross-Site Request Forgery (CSRF) vulnerability in Sourov Amin Word Freshener word-freshener allows Stored XSS.This issue affects Word Freshener: from n/a through <= 1.3.

CWE CWE-352
Vendor sourov amin
Product word freshener
Published Jan 16, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for sourov amin word freshener

Be the first to know when new unknown vulnerabilities affecting sourov amin word freshener are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Sourov Amin / Word Freshener
0 โ‰ค 1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/word-freshener/vulnerability/wordpress-word-freshener-plugin-1-3-csrf-to-stored-xss-vulnerability?_s_id=cve

Credits

SOPROBRO | Patchstack Bug Bounty Program