๐Ÿ” CVE Alert

CVE-2025-30612

UNKNOWN 0.0

WordPress Replace Default Words plugin <= 1.3 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Cross-Site Request Forgery (CSRF) vulnerability in mandegarweb Replace Default Words replace-default-words allows Stored XSS.This issue affects Replace Default Words: from n/a through <= 1.3.

CWE CWE-352
Vendor mandegarweb
Product replace default words
Published Mar 24, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for mandegarweb replace default words

Be the first to know when new unknown vulnerabilities affecting mandegarweb replace default words are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

mandegarweb / Replace Default Words
0 โ‰ค 1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/replace-default-words/vulnerability/wordpress-replace-default-words-plugin-1-3-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve

Credits

Skalucy | Patchstack Bug Bounty Program