VYPR
High severity7.1NVD Advisory· Published Apr 24, 2025· Updated Apr 23, 2026

CVE-2025-46502

CVE-2025-46502

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bas Matthee LSD Custom taxonomy and category meta custom-taxonomy-category-and-term-fields allows Cross Site Request Forgery.This issue affects LSD Custom taxonomy and category meta: from n/a through <= 1.3.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF to Stored XSS in LSD Custom taxonomy and category meta plugin (≤1.3.2) lets attackers force admin actions via crafted requests.

Root

Cause

The LSD Custom taxonomy and category meta WordPress plugin versions up to 1.3.2 are vulnerable to Cross-Site Request Forgery (CSRF) that leads to Stored Cross-Site Scripting (XSS). The plugin fails to properly neutralize input during web page generation while also lacking CSRF protections, allowing an attacker to trick a privileged user into performing unintended actions [1].

Exploitation

Exploitation requires user interaction—an authenticated administrator or other privileged user must click a malicious link, visit a crafted page, or submit a form. The attack does not require the attacker to have any special privileges; they only need to craft a request that, when executed by the victim, modifies plugin settings or taxonomy meta fields to inject malicious scripts [1].

Impact

Successful exploitation allows an attacker to force higher-privileged users (such as admins) to execute unwanted actions under their current authentication session. Since the injected script is stored, it can execute in the context of the admin panel, leading to further compromise, data theft, or site defacement [1].

Mitigation

The vulnerability is present in all versions up to and including 1.3.2. Users are strongly advised to update the plugin to the latest patched version immediately. If an update is not available, the plugin should be temporarily disabled, or the site owner should seek assistance from a hosting provider or developer. This type of vulnerability is known to be used in mass-exploit campaigns targeting WordPress sites [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.