What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover remove-date-and-gravatar-under-comment allows Cross Site Request Forgery.This issue affects Comment Date and Gravatar remover: from n/a through <= 1.0.
Explanation of Vulnerability in Simple Terms
02Summary
The Comment Date and Gravatar remover plugin for WordPress contains a cross-site request forgery (CSRF) vulnerability in versions up to 1.0. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the site without the administrator's knowledge or consent. The vulnerability requires no special privileges but does require the victim to visit a malicious link.
What an attacker can do
03Attacker Capabilities
Perform unwanted administrative actions on the site by tricking a logged-in admin into visiting a malicious webpage.
Potential impact on your site
04Site Impact
An attacker can modify site settings or content through a logged-in admin's browser without the admin's awareness.
Conditions required to exploit
05Prerequisites
Site admin must be logged in and visit an attacker-controlled webpage; no special privileges required.
Key dates
06Disclosure timeline
March 11, 2025
CVE published
April 28, 2026
Record updated