Impact
The vulnerability allows an attacker to exploit a cross‑site request forgery flaw in the Comment‑Emailer plugin, causing arbitrary JavaScript to be stored and later executed inside the browsers of users who view the stored content. This stored XSS can lead to theft of session cookies, defacement, or other malicious client‑side actions, compromising user confidentiality and integrity.
Affected Systems
WordPress sites using the frenchsquared Comment-Emailer plugin up through version 1.0.5 are affected. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity, while the EPSS score is less than 1% which suggests a low probability of exploitation at this time. The vulnerability is not listed in CISA's KEV catalog. Likely, an attacker can trigger the flaw by submitting a crafted CSRF request from an external site, which does not require privileged access to the compromised system.
OpenCVE Enrichment
EUVD