Impact
The vulnerability is a Cross‑Site Request Forgery that allows an attacker to inject and store arbitrary scripts in the wp‑spacecontent plugin settings. Once stored, the scripts run in the browsers of any user who views the affected content, leading to possible data theft, session hijacking, or defacement. The flaw arises from insufficient CSRF protection combined with unsanitized output rendering, making it a Stored XSS flaw that can compromise the confidentiality and integrity of site users.
Affected Systems
WordPress sites using the KokoenDE WP SpaceContent plugin, any version up to and including 0.4.5, are affected. Vulnerable code exists from the earliest released version through 0.4.5.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% suggests the exploit is unlikely to be widely used at present, yet the vulnerability is serious enough to warrant attention. It is not listed in the CISA KEV catalog. Attackers could exploit the flaw by tricking a privileged user into visiting a crafted link that submits a CSRF request; the attack requires authenticated access but can be performed remotely via a URL. The lack of any public exploit mitigates immediate risk, but the low exploitation probability does not eliminate the need for timely patching.
OpenCVE Enrichment
EUVD