Impact
A Cross‑Site Request Forgery flaw in the marcucci Password Protect Plugin for WordPress allows an attacker to submit malicious input without credential validation, which is then stored and delivered to users accessing protected pages. The stored payload is executed in the victim’s browser, enabling JavaScript injection that can deface content, hijack sessions, or run further malicious actions in the context of the site’s users.
Affected Systems
WordPress sites using the Password Protect Plugin for WordPress version 0.8.1.0 or earlier are affected. The plugin is commonly installed to restrict content with a password, so any site relying on it is in risk.
Risk and Exploitability
The CVSS base score of 7.1 signals a high‑severity flaw, while an EPSS score below 1% indicates low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker can craft a CSRF request that steers the plugin’s form submission toward malicious content, which will be stored and served to all users of the protected page, giving the adversary persistent access to the victim’s browser context.
OpenCVE Enrichment
EUVD