Impact
The vulnerability is a CSRF flaw in the TubePress.NET WordPress plugin, which can be exploited by an attacker to forge requests that inject malicious script into stored content. Attackers can create a request that, when executed by an authenticated user, results in stored cross‑site scripting that subsequently runs in visitors’ browsers, potentially compromising confidentiality, integrity and availability of the site.
Affected Systems
All installations of the TubePress.NET plugin from the earliest released version through version 4.0.1 are affected. The plugin is distributed by tubepress:TubePress.NET and is commonly used in WordPress sites that embed video content.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability poses a moderate to high risk. The EPSS score of less than 1% indicates the likelihood of exploitation is low at the current time, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a CSRF attack, which generally requires an authenticated user interaction, such as a logged‑in administrator visiting a crafted link.
OpenCVE Enrichment
EUVD