Impact
The LMB^Box Smileys plugin for WordPress contains a missing nonce validation in its manage_page() function, enabling a Cross‑Site Request Forgery (CSRF) attack. An unauthenticated attacker can forge a request that appears to come from an administrator and change plugin settings, injecting arbitrary web scripts that are stored and later executed by the site. The impact is the introduction of stored XSS, which can compromise administrator credentials, allow session hijacking, or deliver malicious payloads to site visitors.
Affected Systems
Hosts running the LMB^Box Smileys plugin for WordPress with any version up to and including 3.2 are affected. The vulnerability applies to all installations of the plugin that have not yet been upgraded beyond that version threshold.
Risk and Exploitability
The CVSS score of 6.1 signifies a moderate severity, while the EPSS score of less than 1% indicates a very low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to social‑engineer a site administrator into clicking a crafted link that submits the forged request, making the attack vector largely manual but potentially effective against unaware administrators.
OpenCVE Enrichment