Impact
A Cross‑Site Request Forgery flaw in the Tags to Keywords WordPress plugin permits an attacker to inject arbitrary script that is saved to the site’s database. After the injection is stored, any user who views the affected content will execute the attacker’s code. The stored XSS can lead to cookie theft, session hijacking, defacement, or the execution of additional malicious payloads. The issue is rooted in improper validation of form input, as identified by CWE‑352.
Affected Systems
The vulnerability exists in the Tags to Keywords plugin from CheGevara29 for any WordPress installation running version 1.0.1 or earlier. No specific WordPress core version is required beyond the plugin presence.
Risk and Exploitability
The CVSS score of 7.1 reflects a moderate‑to‑high severity, while the EPSS score of less than 1 percent indicates a low probability of exploitation at the time of analysis. The flaw is not currently listed in the CISA KEV catalog. Exploitation would likely require an authenticated WordPress administrator or a victim user who is tricked into visiting a crafted URL that submits the malicious input. Once the payload is stored, every subsequent page view carries the risk of XSS execution for all site visitors.
OpenCVE Enrichment
EUVD