CVE-2025-23804
Published: 16 January 2025
Summary
CVE-2025-23804 is a high-severity CSRF (CWE-352) vulnerability. Its CVSS base score is 7.1 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 28.0th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 SC-23 (Session Authenticity) and SI-15 (Information Output Filtering).
Deeper analysis
CVE-2025-23804 is a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress plugin WP Service Payment Form With Authorize.net, developed by Shiv Prakash Tiwari (plugin slug: wp-service-payment-form-with-authorizenet). The flaw enables Reflected Cross-Site Scripting (XSS) and affects all versions from n/a through 2.6.0 inclusive. It is classified under CWE-352 with a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).
Unauthenticated attackers can exploit this vulnerability remotely with low complexity, though it requires user interaction. By tricking a victim into performing a CSRF-protected action via a malicious webpage or link, the attacker triggers reflected XSS, potentially leading to low-level impacts on confidentiality, integrity, and availability due to the changed scope.
The Patchstack advisory provides details on this CSRF-to-Reflected XSS issue in version 2.6.0 and related mitigation guidance: https://patchstack.com/database/Wordpress/Plugin/wp-service-payment-form-with-authorizenet/vulnerability/wordpress-wp-service-payment-form-with-authorize-net-plugin-2-6-0-csrf-to-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-3436
Vulnerability details
Cross-Site Request Forgery (CSRF) vulnerability in Shiv Prakash Tiwari WP Service Payment Form With Authorize.net wp-service-payment-form-with-authorizenet allows Reflected XSS.This issue affects WP Service Payment Form With Authorize.net: from n/a through <= 2.6.0.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
The CSRF-to-reflected XSS vulnerability in a public-facing WordPress plugin directly enables exploitation of public-facing applications (T1190) and facilitates arbitrary JavaScript execution in the victim's browser (T1059.007).
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Enforces session authenticity mechanisms such as anti-CSRF tokens to prevent unauthorized forged requests that trigger the reflected XSS in this WordPress plugin vulnerability.
Filters information output to web pages to block execution of reflected XSS payloads delivered via the CSRF attack.
Validates inputs at entry points to reject or sanitize malicious payloads that could be reflected as XSS through the CSRF mechanism.