Impact
The Unlimited Page Sidebars plugin contains a cross‑site request forgery flaw that permits an authenticated user—likely one with permission to access the plugin’s administrative form—to submit malicious data that is stored and later rendered as JavaScript, resulting in stored XSS. The missing CSRF token allows forging of requests that bypass normal request validation. It is inferred that the attack requires legitimate access to the form, but the CVE does not explicitly state the exact user role necessary.
Affected Systems
WordPress plugin "Unlimited Page Sidebars" developed by Ederson Peka. Versions from n/a up to and including 0.2.6 are affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis. Attackers would need to target a site running one of the affected plugin versions and exploit the vulnerability by forging a request (likely requiring authentication) that stores a malicious payload, which is later served to all site visitors. Given the low EPSS, widespread exploitation is not yet observed, but the impact could be significant if attackers succeed.
OpenCVE Enrichment
EUVD