Impact
A Cross-Site Request Forgery flaw in the Instabot WordPress plugin enables an attacker to submit a forged request that stores malicious JavaScript code in the site’s database. When other visitors load pages containing the stored content, the injected script executes in their browsers, providing an opportunity for client-side attacks. The weakness stems from insufficient validation of the source of update requests, as indicated by CWE-352.
Affected Systems
All versions of the Instabot plugin up to and including 1.10 are affected. Sites running these releases on WordPress are at risk, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate-to-high severity, while the EPSS score of less than 1 % suggests a low probability of widespread exploitation currently. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires an attacker to deliver a CSRF request, which could be achieved through a malicious link or by compromising an authenticated user’s browser. No publicly available exploit is known, but the attack path remains straightforward for a determined adversary.
OpenCVE Enrichment
EUVD