Impact
The AuthorSure plugin for WordPress suffers from a missing or incorrect nonce validation on the 'authorsure' page, which allows an unauthenticated attacker to perform a Cross‑Site Request Forgery. By forging a request and tricking a site administrator into clicking a malicious link, the attacker can modify plugin settings and inject persistent malicious scripts that are stored on the site. This results in a Stored Cross‑Site Scripting vulnerability capable of compromising the confidentiality, integrity, and availability of the site’s content for all visitors.
Affected Systems
Vulnerable installations are WordPress sites running AuthorSure plugin version 2.3 or earlier. The flaw affects the configuration interface accessed via the 'authorsure' endpoint, thereby impacting all sites that use these affected plugin versions.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity vulnerability. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the flaw is not listed in the CISA KEV catalog. Exploitation requires only that an attacker convince an administrator to click a crafted URL; no privileged access is required. Successful exploitation allows the injection of persistent malicious scripts that execute in the context of an administrator’s or visitor’s browser, potentially leading to data theft, session hijacking, or site defacement.
OpenCVE Enrichment