Impact
The Norby AI plugin for WordPress suffers from a CSRF flaw caused by missing nonce validation on its settings update endpoint. This allows an unauthenticated attacker, by tricking an administrative user into clicking a crafted link, to change the plugin’s configuration and inject arbitrary JavaScript. The vulnerability falls under CWE‑352. The compromised site can then serve malicious scripts to visitors, potentially leading to defacement or further attacks.
Affected Systems
All installations of the Norby AI plugin distributed by jevgenisultanov that are version 1.0.3 or earlier are affected. Any WordPress site that has deployed one of these versions is at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact; the EPSS score of less than 1% implies a very low likelihood of exploitation today. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires social engineering to persuade an authenticated administrator to perform the forged request, meaning that while the attack is technically straightforward, it relies on human manipulation and is therefore less likely to occur automatically.
OpenCVE Enrichment