Kento Splash Screen
Kento Splash Screen has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Kento Splash Screen has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
Kento Splash Screen is installed on roughly 70 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.6.30.
CVE-2025-48351Kento Splash Screen <= 1.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Kento Splash Screen
Author
PluginsPoint
Kento Splash Screen Help you to Display message or HTML content via splash popup box. You can customize the Splash Screen by configuring various settings such as Custom Width of popup box, Custom Height of popup box, Unlimited Background Color, Unlimited Background Image, Custom Border Size, Unlimited Border Color, Custom HTML Content etc. Details and Support Live Preview Plugin Features Fully Responsive. Test Mode. Iframe Support. Custom Width of popup box. Custom Height of popup box. Unlimited Background Color. Unlimited Background Image. Custom Border Size. Unlimited Border Color. Custom HTML Content. Shortcode System. Display any page or post.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C