What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Jeff Starr Simple Statistics for Feeds simple-feed-stats allows Cross Site Request Forgery.This issue affects Simple Statistics for Feeds: from n/a through <= 20250322.
Explanation of Vulnerability in Simple Terms
02Summary
Simple Statistics for Feeds contains a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform unauthorized actions on behalf of a logged-in site administrator. The vulnerability requires the admin to visit a malicious webpage while authenticated. An attacker can modify plugin settings or data, but cannot read sensitive information or cause service disruption.
What an attacker can do
03Attacker Capabilities
Perform unauthorized actions (like changing plugin settings) on behalf of a logged-in administrator.
Potential impact on your site
04Site Impact
Plugin settings could be altered without your knowledge if an admin visits a malicious link while logged in.
Conditions required to exploit
05Prerequisites
Administrator must be logged in and visit an attacker-controlled webpage.
Key dates
06Disclosure timeline
August 22, 2025
CVE published
April 28, 2026
Record updated