LiveActive security incident?Get immediate response
CVE Record

CVE-2013-10025: Exit Strategy Plugin exitpage.php exitpageadmin cross-site request forgery

A vulnerability was found in Exit Strategy Plugin 1.55 on WordPress and classified as problematic. Affected by this issue is the function exitpageadmin of the file exitpage.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. Upgrading to version 1.59 is able to address this issue. The patch is identified as d964b8e961b2634158719f3328f16eda16ce93ac. It is recommended to upgrade the affected component. VDB-225266 is the identifier assigned to this vulnerability.

MediumCVSS 5Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This is a cross-site request forgery issue in the WordPress Exit Strategy Plugin 1.55. An attacker could remotely induce a browser to perform an unintended plugin administration action. The sources describe integrity impact only, not data theft or service outage. Upgrading to version 1.59 is the named fix.

Executive priority

Treat this as a moderate WordPress plugin hygiene issue. It does not show confirmed active exploitation in the supplied sources, but affected sites should be upgraded because the fix is identified and the vulnerability is remotely triggerable.

Technical view

CVE-2013-10025 affects the exitpageadmin function in exitpage.php in Exit Strategy Plugin 1.55 for WordPress. The vulnerability is classified as CWE-352 CSRF with CVSS v2 5.0: AV:N/AC:L/Au:N/C:N/I:P/A:N. The cited fix is commit d964b8e961b2634158719f3328f16eda16ce93ac and version 1.59.

Likely exposure

Exposure is limited to WordPress installations running Exit Strategy Plugin version 1.55. Sites not using this plugin, or already upgraded to 1.59 or later, are not indicated as affected by the provided sources.

Exploitation context

The sources say the attack can be launched remotely, but KEV is false and no cited source states active exploitation. The issue is a CSRF weakness, so practical impact depends on reachable plugin administration behavior and user interaction context.

Researcher notes

Evidence is narrow but consistent: affected component, function, file, CWE, CVSS vector, and fixed version are provided. The source bundle does not include exploit details, affected configuration scope beyond version 1.55, or proof of exploitation.

Mitigation direction

  • Upgrade Exit Strategy Plugin to version 1.59 or later.
  • Disable or remove the plugin if it is not required.
  • Review the referenced patch and vendor guidance before applying compensating controls.
  • Prioritize WordPress sites where administrators actively use this plugin.

Validation and detection

  • Inventory WordPress sites for Exit Strategy Plugin installations.
  • Confirm whether any installed version is 1.55.
  • Verify upgraded instances report version 1.59 or later.
  • Check change management records for patch commit d964b8e961b2634158719f3328f16eda16ce93ac.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-352: User-session and phishing behavior lookup

Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2013-10025 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5 (2.0)
Known Exploited
No
Published

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5CVSS 2.0MediumAV:N/AC:L/Au:N/C:N/I:P/A:N102.9Primary CVE score

Vulnerability scoring details

Base CVSS 2.0 score

5Medium
CVSS 2.0 vector shape for CVE-2013-10025Access VectorAccess ComplexityAuthenticationConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Access Vector
NetworkAdjacentLocal
Access Complexity
LowMediumHigh
Authentication
NoneSingleMultiple
Confidentiality Impact
CompletePartialNone
Integrity Impact
CompletePartialNone
Availability Impact
CompletePartialNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/aExit Strategy Plugin1.55Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-352 · source CWE mapping

Cross-Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF) represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.