CVE-2025-23870
📛 CVE Title
WordPress Copyright Safeguard Footer Notice plugin <= 3.0 - CSRF to Stored Cross Site Request Forgery (CSRF) vulnerability
Description
Cross-Site Request Forgery (CSRF) vulnerability in wygk Copyright Safeguard Footer Notice copyright-safeguard-footer-notice allows Stored XSS.This issue affects Copyright Safeguard Footer Notice: from n/a through <= 3.0.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Patchstack
- CVSS severity
- HIGH
- CVSS score
- 7.1 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L- Effective score
- 7.1 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-352 - Reserved
- 2025-01-16
- Published
- 2025-01-16 21:07 UTC
- Last updated
- 2026-04-28 18:11 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/23xxx/CVE-2025-23870.json
- Linked Threat
- CVE-2025-23870 — Copyright Safeguard Footer Notice <= 3.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2025-01-16 21:15:27 UTC
- NVD last modified
- 2026-06-17 08:57:38 UTC
- NVD CVSS v3.1
- 7.1 / 10 HIGH source: audit@patchstack.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L- Exploitability subscore
- 2.8 / 10
- Impact subscore
- 3.7 / 10
- EPSS score
- 0.0020 (probability of exploitation in next 30 days)
- EPSS percentile
- 10.11% vs all CVEs — higher = more likely to be exploited, as of 2026-07-26
NVD / KEV / EPSS data refreshed 2026-07-27 02:38 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2025-3491 - Assigner
- Patchstack
- Published
- Jan 16, 2025, 8:07:27 PM
- Updated
- Apr 28, 2026, 4:11:22 PM
- EUVD base score (CVSS 3.1)
-
7.1 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L - EUVD-reported EPSS
- 0.1400
- Vendors
- Robert Nicholson, wygk
- Products
-
Copyright Safeguard Footer Notice (0 ≤3.0)Copyright Safeguard Footer Notice (n/a ≤3.0)
- Aliases
-
GHSA-f2jg-6m5f-xqx7
ENISA description: Cross-Site Request Forgery (CSRF) vulnerability in wygk Copyright Safeguard Footer Notice copyright-safeguard-footer-notice allows Stored XSS.This issue affects Copyright Safeguard Footer Notice: from n/a through <= 3.0.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| wygk | Copyright Safeguard Footer Notice |
0 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
MITRE references (1) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
Indicators (2)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| domain |
xss.this
|
no local data | 2026-05-18 21:19 UTC |
| cve |
CVE-2025-23870
|
no local data | 2026-06-06 14:02 UTC |
Remediations (20)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
Wordfence remediation: Copyright Safeguard Footer NoticeWordfence
No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
2026-06-06 14:02 UTC -
web:cybersecuritynews.com
Microsoft has disclosed a critical zero-day vulnerability in Windows BitLocker, tracked as CVE -2026-45585, that allows threat actors with physical access to bypass full-disk encryption entirely, potentially exposing sensitive data within minutes.
2026-05-22 12:32 UTC -
web:epatch.pa.gov
Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...
2026-05-22 12:32 UTC -
web:github.com
A new and improved community patch for BO3. . Contribute to shiversoftdev/t7patch development by creating an account on GitHub.
2026-05-22 12:32 UTC -
web:patch.com
The best breaking news, stories, and events from the Patch network of local news sites
2026-05-22 12:32 UTC -
web:patch.moe
Age Verification Are you 18 years or older? YES NO
2026-05-22 12:32 UTC -
web:blog.protiviti.com
Vulnerability prioritization in the age of Mythos requires smarter backlog management, faster patching, and reduced exposure as vulnerability noise and attack paths increase.
2026-05-22 12:32 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's October 2025 Patch Tuesday, which includes security updates for 172 flaws, including six zero-day vulnerabilities. Get patching!
2026-05-22 12:32 UTC -
web:www.csoonline.com
Days after Microsoft patched a high-severity issue affecting its Windows Defender antivirus tool through April's Patch Tuesday, researchers warn of another vulnerability that could enable SYSTEM ...
2026-05-22 12:32 UTC -
web:www.patchcareerinstitute.com
P.A.T.C.H . Career Institute's mission is to provide quality training to students in the medical and vocational field. Our primary focus is to provide affordable, and competitive educational training for low to moderate income students.
2026-05-22 12:32 UTC -
web:www.cisa.gov
Updated October 29, 2025 : CISA has updated this Alert to include revised information on vulnerable product identification, potential threat activity detections, and additional resources. Microsoft released an update to address a critical remote code execution vulnerability impacting Windows Server Update Service (WSUS) in Windows Server (2012, 2016, 2019, 2022, and 2025 ), CVE - 2025 -59287
2026-05-22 02:40 UTC -
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
2026-05-22 02:40 UTC -
web:www.windowslatest.com
Microsoft has confirmed that the Windows 11 January 2026 Update is causing at least three major issues, rolling out fixes for two bugs.
2026-05-22 02:40 UTC -
web:www.esri.com
Scope - This vulnerability does NOT affect feature services utilizing only hosted feature layers. Mitigation - A Web Application Firewall (WAF) is strongly recommended for Internet-facing systems as described in the ArcGIS Enterprise Hardening Guide located within the ArcGIS Trust Center documents section.
2026-05-22 02:40 UTC -
web:www.ninjaone.com
Overview KB5087054 is a cumulative security and reliability update for the .NET Framework targeting Windows 11 version 24H2 systems. Released on May 12, 2026, this patch addresses critical vulnerabilities affecting both .NET Framework 3.5 and 4.8.1 installations. The update is designed to be deployed as part of standard maintenance routines and is available through multiple distribution ...
2026-05-22 02:40 UTC -
web:www.oracle.com
This Critical Patch Update contains 374 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at October 2025 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 02:40 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-05-22 02:40 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 02:40 UTC -
web:www.bleepingcomputer.com
Microsoft says customers in restricted network environments may encounter Windows Update failures after installing the January 2026 optional non-security preview updates.
2026-05-22 02:40 UTC -
web:www.techrepublic.com
Microsoft's April 2026 Patch Tuesday fixes 165 vulnerabilities, including two zero-days, in one of the company's largest monthly security updates.
2026-05-22 02:40 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2025-23870.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-23870",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-01-17T17:17:28.113609Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-01-17T19:04:49.800Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "copyright-safeguard-footer-notice",
"product": "Copyright Safeguard Footer Notice",
"vendor": "wygk",
"versions": [
{
"lessThanOrEqual": "3.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "SOPROBRO | Patchstack Bug Bounty Program"
}
],
"datePublic": "2026-04-01T16:33:37.280Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Cross-Site Request Forgery (CSRF) vulnerability in wygk Copyright Safeguard Footer Notice copyright-safeguard-footer-notice allows Stored XSS.<p>This issue affects Copyright Safeguard Footer Notice: from n/a through <= 3.0.</p>"
}
],
"value": "Cross-Site Request Forgery (CSRF) vulnerability in wygk Copyright Safeguard Footer Notice copyright-safeguard-footer-notice allows Stored XSS.This issue affects Copyright Safeguard Footer Notice: from n/a through <= 3.0."
}
],
"impacts": [
{
"capecId": "CAPEC-592",
"descriptions": [
{
"lang": "en",
"value": "Stored XSS"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-352",
"description": "Cross-Site Request Forgery (CSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-28T16:11:22.937Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/Wordpress/Plugin/copyright-safeguard-footer-notice/vulnerability/wordpress-copyright-safeguard-footer-notice-plugin-3-0-csrf-to-stored-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
}
],
"title": "WordPress Copyright Safeguard Footer Notice plugin <= 3.0 - CSRF to Stored Cross Site Request Forgery (CSRF) vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2025-23870",
"datePublished": "2025-01-16T20:07:27.326Z",
"dateReserved": "2025-01-16T11:31:20.771Z",
"dateUpdated": "2026-04-28T16:11:22.937Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}