Impact
A CSRF vulnerability in albdesign Simple Project Manager allows an attacker to submit malicious input that the plugin stores and later renders when project data is viewed. Because the stored input is executed in the browser of any user who views the project, the attack can lead to session hijacking, defacement, or arbitrary code execution within the site’s context.
Affected Systems
The affected software is the WordPress Simple Project Manager plugin from albdesign. All released versions from the initial release through version 1.2.2 are vulnerable. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑relevance vulnerability, while the EPSS score of < 1% shows that exploitation is currently unlikely. The issue is not listed in the CISA KEV catalog. Exploitation requires an authenticated request to the plugin’s endpoint, most likely performed through a forged POST request from a victim’s browser, resulting in stored malicious content that is subsequently rendered to other users. The CSRF flaw makes this a practical attack vector for an adversary who can embed the attack in a link or form that a user will unknowingly submit.
OpenCVE Enrichment
EUVD