Impact
The vulnerability is a Cross‑Site Request Forgery flaw that enables an attacker to inject JavaScript code that will be stored in the WordPress site. Once the malicious script is stored, every visitor will execute it, potentially stealing credentials, session cookies, or executing additional exploits. The flaw is a CWE‑352 weakness and does not grant direct control of the server, but it can be used for social engineering or further credential theft.
Affected Systems
Any WordPress installation that has the DigiTimber cPanel Integration plugin version 1.4.6 or earlier is affected. The plugin is available for all roles that can edit content, so the risk extends to sites where the plugin is active.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of <1% suggests that, at the time of analysis, the likelihood of exploitation was considered very low. The vulnerability is not listed in the CISA KEV catalog. An attacker who can perform CSRF—typically by tricking an authenticated administrator or user into visiting a crafted link—could inject the stored script. No additional system privilege is required beyond that authenticated role, making the attack relatively easy to execute if social engineering succeeds.
OpenCVE Enrichment
EUVD