Impact
A cross‑site request forgery flaw in the WordPress plugin Visit Site Link enhanced allows an attacker to inject arbitrary script that is stored within the site. The malicious script is persisted in the plugin’s database and executed whenever a site visitor loads a page that processes that stored input, thereby compromising the confidentiality and integrity of users’ browsers. This weakness is a CWE‑352, a Cross‑Site Request Forgery issue.
Affected Systems
The vulnerability affects the plugin published by xavsio4, titled Visit Site Link enhanced, in all releases from its initial version through version 1.0. Users running any of these versions are exposed.
Risk and Exploitability
With a CVSS score of 7.1 the flaw is considered moderate severity, but the EPSS score is reported below 1% and the vulnerability is not listed in CISA KEV, indicating low likelihood of widespread exploitation. Attackers would need to trigger the CSRF condition – for example by tricking an authenticated user or administrator into submitting a forged request – to embed the payload. Once stored, the payload runs in the context of any visitor, potentially enabling credential theft, session hijacking, or further propagation.
OpenCVE Enrichment
EUVD