cvemon logocvemon logo

Activity

Trending

CVEs

CVE-2025-26768

Published Feb 16, 2025

Last updated 6 days ago

  1. Overview

  2. Weaknesses

  3. Social media

  4. References

Overview

Description
Cross-Site Request Forgery (CSRF) vulnerability in what3words what3words Address Field 3-word-address-validation-field allows Stored XSS.This issue affects what3words Address Field: from n/a through <= 4.0.15.
Source
audit@patchstack.com
NVD status
Awaiting Analysis

Weaknesses

audit@patchstack.com
CWE-352

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2025-26768 🔴 HIGH (7.1) 🏢 what3words - what3words Address Field 🏗️ Unknown Version 🔗 https://t.co/RYz6UPAfGS #CyberCron #VulnAlert https://t.co/Tr15w0lkb7

    @cybercronai

    18 Feb 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-26768 Cross-Site Request Forgery (CSRF) vulnerability in what3words what3words Address Field allows Stored XSS. This issue affects what3words Address Field: from n/a throug… https://t.co/70lALq62SS

    @CVEnew

    16 Feb 2025

    452 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.

  • https://nvd.nist.gov/vuln/detail/CVE-2025-26768
  • https://patchstack.com/database/Wordpress/Plugin/3-word-address-validation-field/vulnerability/wordpress-what3words-address-field-plugin-4-0-15-csrf-to-stored-xss-vulnerability?_s_id=cve
TRY INTRUDER
Intruder logo

© 2026 Intruder Systems Ltd.

AboutPrivacySitemapFeeds