Impact
The Geotagged Media plugin for WordPress contains a Cross‑Site Request Forgery flaw that allows an attacker to insert malicious script that is stored in the site’s database. Once stored, the script will execute in the browsers of any user who loads the relevant content, enabling the attacker to steal credentials, alter session data, or deface the site. This stored XSS can be used to compromise confidentiality and integrity for all site visitors.
Affected Systems
The vulnerability affects the Geotagged Media plugin developed by Digital Fisherman, version 0.3.0 and all earlier releases. WordPress sites that have installed any of these plugin versions are at risk.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity. The EPSS score is below 1%, indicating a relatively low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. The likely attack vector is a forged HTTP request that an authenticated administrator inadvertently submits, causing the malicious script to be stored. Once exfiltrated, the script can run for any subsequent visitor, posing a serious threat to user data.
OpenCVE Enrichment
EUVD