Impact
The vulnerability is a Cross‑Site Request Forgery (CWE‑352) that permits an attacker to submit malicious content which is then stored in the WordPress post and executed when other users view the post. This results in Stored XSS, potentially exposing site visitors to data theft or session hijacking.
Affected Systems
The affected software is the WordPress plugin "MD Custom content after or before of post" developed by Mukesh Dak. Versions from the first release up to and including 1.0 are impacted. The plugin is installed on WordPress sites and allows administrators to insert custom markdown content before or after posts.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity, while the EPSS score of less than 1% suggests low exploitation probability in the wild. The vulnerability is not listed in the CISA KEV catalog, and there is no publicly known exploit. The attack vector is likely via CSRF, meaning an attacker needs a logged‑in user (or site admin) to be tricked into submitting malicious content. The overall risk is moderated by the low EPSS but remains significant if the plugin remains at an affected version.
OpenCVE Enrichment
EUVD