CVE-2025-62956
8.8iseremet · Reloadly
A CSRF vulnerability in the iseremet Reloadly plugin allows an unauthenticated attacker to perform Stored Cross-Site Scripting (XSS) attacks.
Executive summary
The iseremet Reloadly plugin is vulnerable to a CSRF-based Stored XSS attack, which could allow unauthenticated attackers to execute malicious scripts in the context of a user session.
Vulnerability
The vulnerability is a Cross-Site Request Forgery (CWE-352) flaw that enables Stored Cross-Site Scripting. An unauthenticated attacker can trick an administrator or user into performing unintended actions that result in the injection of malicious scripts into the application.
Business impact
Successful exploitation of this vulnerability can lead to the compromise of user sessions, potential theft of administrative credentials, and the injection of unauthorized content into the website. With a CVSS score of 8.8, this flaw represents a high risk to data integrity and site security, necessitating prompt attention to prevent unauthorized script execution.
Remediation
Immediate Action: Since a specific patch version is currently unknown, users should monitor the official Patchstack database for version 2.0.2 or higher. If the plugin is not essential, consider deactivating or removing it from the environment until a vendor-supplied fix is verified.
Proactive Monitoring: Review web server and application access logs for suspicious requests involving the reloadly-topup-widget endpoint, particularly those originating from unknown or unauthorized sources.
Compensating Controls: Implement a robust Web Application Firewall (WAF) to detect and block malicious cross-site requests and injected scripts before they reach the plugin.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
This vulnerability presents a significant risk due to its potential for script injection and session hijacking. Organizations using the Reloadly plugin should prioritize monitoring for security updates and apply the latest version immediately upon release to remediate this high-severity flaw.
Sources
Originally found and disclosed by Nguyen Xuan Chien | Patchstack Bug Bounty Program, per the CVE Program record.