Impact
The My-Related-Posts plugin for WordPress contains a Cross‑Site Request Forgery flaw that enables an attacker to store malicious script payloads in the plugin’s data. Once stored, the script is served to visitors, resulting in full page compromise and potential credential theft or session hijacking. This weakness maps to CWE‑352, highlighting the failure to validate request authenticity prior to modifying stored data.
Affected Systems
The flaw affects the isnowfy My-Related-Posts WordPress plugin through version 1.1. Any site running an affected version of this plugin is at risk until the issue is patched or mitigated.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability represents a high‑severity risk. The EPSS score of less than 1% indicates that exploitation is currently uncommon, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker tricking an authenticated user or admin of the WordPress site into loading a specially crafted URL that triggers the CSRF controlled request, thereby persisting a stored XSS payload.
OpenCVE Enrichment
EUVD