CVE-2025-23823: WordPress CNZZ&51LA for WordPress plugin <= 1.0.1 - CSRF to Stored XSS vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in jprintf CNZZ&51LA for WordPress cnzz51la-for-wordpress allows Cross Site Request Forgery.This issue affects CNZZ&51LA for WordPress: from n/a through <= 1.0.1.
Security readout for executives and security teams
Plain-English summary
CVE-2025-23823 affects the CNZZ&51LA for WordPress plugin through version 1.0.1. The reported issue is CSRF leading to stored XSS, meaning a tricked site user could cause malicious content to be saved in the WordPress site. Business risk is mainly site compromise, visitor exposure, and trust damage.
Executive priority
Treat as a high-priority WordPress plugin risk if the plugin is deployed. Prioritize inventory first, then remove, disable, or update based on vendor guidance. No source in the bundle confirms active exploitation, so urgency is exposure-driven rather than KEV-driven.
Technical view
The source bundle identifies CWE-352 in jprintf CNZZ&51LA for WordPress, package cnzz51la-for-wordpress, through <= 1.0.1. CVSS 3.1 is 7.1: network exploitable, low complexity, no attacker privileges, user interaction required, changed scope, and low confidentiality, integrity, and availability impact.
Likely exposure
Exposure appears limited to WordPress sites with CNZZ&51LA for WordPress installed at version 1.0.1 or earlier. The bundle does not confirm a fixed version, exact vulnerable endpoint, or required victim role. Sites without this plugin are not indicated as affected.
Exploitation context
The bundle does not cite CISA KEV listing or active exploitation. Exploitation should not be treated as confirmed. The CVSS vector indicates a remote attacker needs user interaction, consistent with CSRF, and the title indicates stored XSS impact.
Researcher notes
Evidence is sparse. The title states CSRF to stored XSS, while the CVE description emphasizes CSRF. The provided data does not include proof-of-concept details, patch status, vulnerable parameter, endpoint, or role requirements. Avoid assuming exploitability beyond the CVSS vector and Patchstack classification.
Mitigation direction
Inventory WordPress sites for cnzz51la-for-wordpress installations.
If present at <=1.0.1, check vendor and Patchstack guidance for an update.
Disable or remove the plugin if it is not business-critical.
Limit administrative WordPress access while remediation is pending.
Monitor site content and plugin settings for unexpected script changes.
Validation and detection
Confirm whether CNZZ&51LA for WordPress is installed.
Record the installed plugin version on each WordPress site.
Compare versions against the reported affected range, <=1.0.1.
Review Patchstack and CVE records for updated remediation details.
Check for unexpected stored scripts or unauthorized settings changes.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-352: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-352 · source CWE mapping
Cross-Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.